Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.php > #3655
| From | Balazs Nadasdi <yitsushi@gmail.com> |
|---|---|
| Newsgroups | comp.lang.php |
| Subject | Re: session cookie: client side |
| Date | 2011-11-03 05:23 -0700 |
| Organization | http://groups.google.com |
| Message-ID | <4147316.976.1320323017283.JavaMail.geo-discussion-forums@yqnv12> (permalink) |
| References | <j8tlr0$idi$1@news.albasani.net> |
I don't know I understood your question totally but... If the user can read the session cookie then any others can read the session cookie. The browser can't recognize who sits in front of the monitor. Another way: If user can read session cookie + it's not an SSL channel -> any others can sniff it (local machine or another machine on the route/wifi) Mechanism: on server side the system generates a Session ID (SID). The SID identifies the session datas ($_SESSION in PHP). The Server store session data in a file or database. on client side the client knows only the SID but the client doesn't know session data, only ID. Client sends its SID, the server find data. So... for example: If you test IP of the client and SID your can secure the session from outside of the box but you can't do it with inside of the box. Use SSL + check IP + never-never-ever store important information in cookies.
Back to comp.lang.php | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
session cookie: client side "sl@exabyte" <sb5309@hotmail.com> - 2011-11-03 17:10 +0800
Re: session cookie: client side Balazs Nadasdi <yitsushi@gmail.com> - 2011-11-03 05:23 -0700
Re: session cookie: client side "sl@exabyte" <ecp_gen@my-rialto.com> - 2011-11-04 14:14 +0800
Re: session cookie: client side Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-04 07:55 -0400
Re: session cookie: client side "sl@exabyte" <sb5309@hotmail.com> - 2011-11-04 22:21 +0800
Re: session cookie: client side Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-04 14:40 -0400
Re: session cookie: client side Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-04 15:53 +0000
Re: session cookie: client side Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-04 14:41 -0400
Re: session cookie: client side Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-04 15:52 +0000
csiph-web