Re: [Phplib-users] store the IP in the session
Brought to you by:
nhruby,
richardarcher
From: Giancarlo <gia...@na...> - 2002-12-04 18:16:13
|
> Why not to finish all these IP discussions then? Let's simply trigger the > user to use SSL for safer sessions, which is fairly easy to do if you've Excuse me, but if I propose you to click on a link as https://phplib.sourceforge.net/showoff.php3?PHPSESSID=1 you click on it, you login, you place it in your bookmarks, can't I steal it afterwards, forever and ever, as long as you use that bookmark? The typical illiterate snooper exploit is just this. Gian |