Re: [PHP4BETA] Forcing a new Session ID?
| From: | Sascha Schumann | Date: | Tue, 26 Oct 1999 20:24:08 +0000 |
| Subject: | Re: [PHP4BETA] Forcing a new Session ID? | ||
| References: | 1 | Groups: | php.version4 |
| Request: | Send a blank email to php-version4+get-5716@lists.php.net to get a copy of this message | ||
On Mon, Oct 25, 1999 at 08:25:20PM -0400, Jon E. Mitchiner wrote:
> Im trying to implement some security routines with the Session ID processing
> so if someone tries hijacking someone else's session based on certain
> variables that fail then they will be forced to get a new session id.
>
> Ive been trying to figure this out, but have had no luck. What would be the
> best way to do this -without- destroying the existing user's session.
If you think that a specific session was hijacked, destroy
the session. I don't see any point in trying to rescue the
session (if a session id was leaked once, there is a high
propability that it will happen again). Thus, we supply only
session_destroy().
--
Regards,
Sascha Schumann
Consultant