note 57901 added to function.session-set-save-handler
| From: | php-general at lists dot php dot net | Date: | Tue, 18 Oct 2005 16:04:51 +0000 |
| Subject: | note 57901 added to function.session-set-save-handler | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-97175@lists.php.net to get a copy of this message | ||
One way to prevent session stealing is to implement an IP wrapper round the session data. Make
another field in ur mysql database, and whenever data is written, also insert the ip, and when it is
read, check the ip. This makes sure the the session data ONLY goes back to the ip it was sent from.
This removes one of the problems in session handling
----
Manual Page -- http://www.php.net/manual/en/function.session-set-save-handler.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+57901
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+57901&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+57901&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+57901&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+57901&report=yes&reason=useless
Delete: non-english -- http://master.php.net/manage/user-notes.php?action=delete+57901&report=yes&reason=non-english
Delete: already in docs -- http://master.php.net/manage/user-notes.php?action=delete+57901&report=yes&reason=already+in+docs
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+57901&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+57901&report=yes
Search -- http://master.php.net/manage/user-notes.php