From: order t. c. <ke...@go...> - 2001-11-01 22:53:37
hi!
did anyone code something that checks other infos beside cookies to check
session validity? (like az ip, and an md5 of some client info for eg.)
coz anyone stealing the cookie could be logged in, so it's no matter if you
send the password in md5 or not.. :P
anyone?
keo
--
don't believe everything you think.