Re: [PHP4BETA] Session Cookies With External Reference Checking Not Working; Patch Attached
| From: | Sascha Schumann | Date: | Tue, 29 Feb 2000 10:51:32 +0000 |
| Subject: | Re: [PHP4BETA] Session Cookies With External Reference Checking Not Working; Patch Attached | ||
| References: | 1 2 3 | Groups: | php.version4 |
| Request: | Send a blank email to php-version4+get-11182@lists.php.net to get a copy of this message | ||
> Right, but much more likely the user will send the link in an e-mail.
> Or even if it's on a homepage, anyone with a bit of knowledge of php
> will know to cut and paste to exploit the security hole, rather than
It's not a security hole.
> of it. This would only require a run-time directive to enable/disable
> REMOTE_ADDR checking.
You underestimate the REMOTE_ADDR thing. As one promiment
example, Hotmail used such a check, but dropped it very
quickly, because many users had problems to access their
site. You might want to read "Branding a browser" by Kristian
Köhntopp (somewhere on phplib.netuse.de).
--
Regards,
Sascha Schumann
Consultant
Attachment: [application/pgp-signature]
Attachment: [application/pgp-signature]