aj123cd Posted April 2, 2012 Share Posted April 2, 2012 Stop using JS to steal session id, I thought of using the following code, can anyone advise is it good practice? Ini_set(‘session.cookie_httponly’, true); Link to comment https://forums.phpfreaks.com/topic/260191-session-hijacking/ Share on other sites More sharing options...
aj123cd Posted April 2, 2012 Author Share Posted April 2, 2012 can any one advice me? Link to comment https://forums.phpfreaks.com/topic/260191-session-hijacking/#findComment-1333655 Share on other sites More sharing options...
floridaflatlander Posted April 2, 2012 Share Posted April 2, 2012 Someone posted this info before http://phpsec.org/projects/guide/4.html Link to comment https://forums.phpfreaks.com/topic/260191-session-hijacking/#findComment-1333663 Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.