|
Posted by Michael Fesser on 06/24/07 13:01
..oO(David T. Ashley)
>However, when a session is opened on my systems, there is some server-side
>state held to remember the session and related data, including the IP. If
>there is another connection made using the same session ID from a different
>IP, the software assumes that it is a forgery, kills the session(s)
>involved, and writes alarming things in the logfiles.
This might lead to many false alarms. An IP is not unique to a
particular visitor.
Micha
Navigation:
[Reply to this message]
|