note 39770 deleted from function.session-regenerate-id by nlopess
| From: | nlopess@php.net | Date: | Tue, 10 Feb 2004 18:31:19 +0000 |
| Subject: | note 39770 deleted from function.session-regenerate-id by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-64975@lists.php.net to get a copy of this message | ||
Note Submitter: dizit@mail.ru
----
>>gmirchev at usa dot net
For preventing session fixation attack you must unset possible variable not only in $_COOKIE.
Session id may be passed including via GET, POST, requests.
There is a need to unset session ID in $_COOKIE, $_GET, $_POST