Reply to Re: Is PHP session safe?

Your name:

Reply:


Posted by Jerry Stuckle on 06/12/07 03:19

Roman wrote:
> iktorn wrote:
>> howa napisał(a):
>>> 1. For example, without SSL, If I capture my local LAN packet and
>>> scanned the SESSION ID, is it possible to hijack the session?
>>>
>> unfortunately yes
>>
>>> 2. So any recommendation for web apps session handling without SSL?
>>>
>> - use very short session life time
>> - force user to login again before doing something important
>>
>
> How about caching the initiating IP during session creation? Unless
> potential hijacker is behind same NAT box, he will have have different
> IP and should not be able to hijack.
>
> Roman

And what do you do when the IP address can change with every request -
for instance, AOL users and some corporations?

--
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@attglobal.net
==================

[Back to original message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация