Re: [PHP] Proposal for securing PHP sessions

2002-09-08 Thread Chris Shiflett
I think you are definitely on the right track here, though I unfortunately haven't had time to look at your code (thus, I'm just going by your description). Due to frequent vulnerabilities found in Internet Explorer's cookie handling (versions 4.0 - 6.0 allow anyone to view cookies from any d

[PHP] Proposal for securing PHP sessions

2002-09-07 Thread mar tin
Dear all: Until I read the article "PHP Session security" (http://www.webkreator.com/php/configuration/php-session-security.html) I haven't noticed how insecure PHP Sessions are. Basically there're 2 problems: *) It's possible to hijack a session if you know the SID (session id) 1) If you