Jump to content

[SOLVED] $_SESSION security


dadamssg

Recommended Posts

the $_SESSION array is pulled from a temporary file on the server in which can only be modified by applications on the server. If someone can use an external program to modify the sessions, then you have larger issues. If your on a shared host, I'm not 100% sure that the sessions are safe from someone on the same server grabbing em.

is there anything i need to know about the security of using sessions? can you set them via another program or something like that? if so should i have the session names something obscure so they will never guess it?

 

if sessions aren't safe, we are all screwed....

 

we'd have to rework how we do logins and stuff....

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.