Forcing a new Session ID?
| From: | Jon E. Mitchiner | Date: | Tue, 26 Oct 1999 00:25:20 +0000 |
| Subject: | Forcing a new Session ID? | ||
| Groups: | php.version4 | ||
| Request: | Send a blank email to php-version4+get-5696@lists.php.net to get a copy of this message | ||
Im trying to implement some security routines with the Session ID processing
so if someone tries hijacking someone else's session based on certain
variables that fail then they will be forced to get a new session id.
Ive been trying to figure this out, but have had no luck. What would be the
best way to do this -without- destroying the existing user's session.
I tried stuff like:
$newsid = md5(rand);
session_name($newsid); -or- session_id($newsid);
Neither one seems to have any change or affects the session id.
Suggestions, ideas, etc would be appreciated.
Thanks!
Jon Mitchiner
ICQ # 21030881
AIM # MinotaurT