Jump to content

Session security question


spfoonnewb

Recommended Posts

I have a login script that uses sessions and cookies, all the session will contain is the username of the user, and the password they are using (Encrypted).

Each page behind that is using that session username and password, and testing it against the database before doing anything. If it doesn't match the database.. i.e it has been edited it redirects to the login page to fix the session.

Right now I am forcing cookies, do you think that allowing PHPSID's would be a security vulnerability?

[code]<?php
SetCookie("COOKIE", "TEST");

if ($COOKIE == "TEST") {

} else {
header("location:cookies.php");
}
?> [/code]
Link to comment
https://forums.phpfreaks.com/topic/35965-session-security-question/
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.