Posted by Toby A Inkster on 06/24/07 16:05
David T. Ashley wrote:
> I don't know what security best practices are for sessions, but I think if
> the IP changes during a session it would be unusual.
Not particularly unusual. My office has three ADSL connections with
different IPs, and a load-balancing router. If a user in the office made
two page requests from your site, there is a 67% chance that they would
come from different IP addresses.
Such a network configuration is not particularly unusual. Many routers
aimed at offices of 50-200 people allow for load balancing between two or
more Internet connections.
--
Toby A Inkster BSc (Hons) ARCS
[Geek of HTML/SQL/Perl/PHP/Python/Apache/Linux]
[OS: Linux 2.6.12-12mdksmp, up 3 days, 19:41.]
A New Look for TobyInkster.co.uk
http://tobyinkster.co.uk/blog/2007/06/22/new-look/
[Back to original message]
|