Menu

#18 security / session spoofing

open
nobody
None
5
2002-01-11
2002-01-11
Anonymous
No

When using a proxy web server for the client, all
remote IPs appear the same to the server. This allows
someone to spoof a session very easily(confirmed).
Please find another way to authenticate a session
(client-side cookies?).

Also, can the time-out on a session be configurable
(even just a Makefile variable would be good).

Discussion


Log in to post a comment.

Want the latest updates on software, tech news, and AI?
Get latest updates about software, tech news, and AI from SourceForge directly in your inbox once a month.