note 57901 deleted from function.session-set-save-handler by jome
| From: | jome@php.net | Date: | Tue, 18 Oct 2005 17:14:01 +0000 |
| Subject: | note 57901 deleted from function.session-set-save-handler by jome | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-97178@lists.php.net to get a copy of this message | ||
Note Submitter:
Reason: bad code
----
One way to prevent session stealing is to implement an IP wrapper round the session data. Make
another field in ur mysql database, and whenever data is written, also insert the ip, and when it is
read, check the ip. This makes sure the the session data ONLY goes back to the ip it was sent from.
This removes one of the problems in session handling