Re: [PHP4BETA] Forcing a new Session ID?
| From: | Sascha Schumann | Date: | Wed, 27 Oct 1999 12:22:15 +0000 |
| Subject: | Re: [PHP4BETA] Forcing a new Session ID? | ||
| References: | 1 2 3 4 | Groups: | php.version4 |
| Request: | Send a blank email to php-version4+get-5726@lists.php.net to get a copy of this message | ||
On Wed, Oct 27, 1999 at 12:18:37PM +0100, Michaël Parienti wrote:
> Sascha Schumann a écrit :
> >
> > Yes, this can create fascinating scenarios. An existing
> > workaround is to set session.extern_referer_check to the
> > domain of your site. If a request's referer does not contain
> > that text string, the session id is discarded.
> >
>
> And what about a verification with IP adresse of the client?
That is based on assumptions which fail in the real world.
--
Regards,
Sascha Schumann
Consultant