Posted by iktorn on 06/11/07 14:57
howa napisał(a):
> 1. For example, without SSL, If I capture my local LAN packet and
> scanned the SESSION ID, is it possible to hijack the session?
>
unfortunately yes
> 2. So any recommendation for web apps session handling without SSL?
>
- use very short session life time
- force user to login again before doing something important
--
Wiktor Walc
http://phpfreelancer.net
Navigation:
[Reply to this message]
|