note 27689 added to ref.session

From: Date: Mon, 16 Dec 2002 06:01:15 +0000
Subject: note 27689 added to ref.session
Groups: php.notes 
Request: Send a blank email to php-notes+get-40943@lists.php.net to get a copy of this message
The easiest (and therefor, most vulnerable) method of validating a session is to just keep a copy of the REMOTE_IP in $_SESSION, and compare it at the beginning of your script. Of course this doesnt prevent someone from blindly sending things to your server and getting no reply, but I think it will do a pretty good job of preventing someone from hijacking your session in order to get ahold of an order confirmation page that has your address and CC# on it. As a general rule: Keep track of your users. NEVER allow POST data for things like online purchases without making sure that the last page they were on is the page that should be making that POST (and I dont mean checking the referer: header. This kind of thing is what the _SESSION variable can be good for storing) -- http://www.php.net/manual/en/ref.session.php http://master.php.net/manage/user-notes.php?action=edit+27689 http://master.php.net/manage/user-notes.php?action=delete+27689 http://master.php.net/manage/user-notes.php?action=reject+27689

« previous php.notes (#40943) next »