duanju8431 2017-03-31 15:58
浏览 711
已采纳

使用PHPSESSID和cookie识别用户

As far as I know webapps use session_start(); that implicitly create the session cookie PHPSESSID to recognize his users,

but when analysing the outgoing HTTP requests toward differents web applications (yahoo, facebook, gmail, youtube) I didn't see this cookie in the HTTP header but another ones :

sid, ssid, gmail_at, apisid, sapisid in gmail

datr, lu, c_user, xs, fr in facebook...

is one of these cookies is the same as PHPSESSID/JSESSID and they rename it ? (I don't think so, they don't have the same length)

is there another way that session_start() and URL Rewriting to distinguish sessions ?

or they create manually the session IDs with setcookie(); ? what is the advantage then ?

  • 写回答

1条回答 默认 最新

  • dtfpznrbn503027700 2017-03-31 16:02
    关注

    You can rename the session cookie and alter the hash algo

    Try session_name($newName) to change PHPSESSID.

    Or change the cookie value itself with session_id($string)

    Also its a server configuration/app behaviour thing. You can safe your cookie to user relation in a file, or in a table.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 素材场景中光线烘焙后灯光失效
  • ¥15 请教一下各位,为什么我这个没有实现模拟点击
  • ¥15 执行 virtuoso 命令后,界面没有,cadence 启动不起来
  • ¥50 comfyui下连接animatediff节点生成视频质量非常差的原因
  • ¥20 有关区间dp的问题求解
  • ¥15 多电路系统共用电源的串扰问题
  • ¥15 slam rangenet++配置
  • ¥15 有没有研究水声通信方面的帮我改俩matlab代码
  • ¥15 ubuntu子系统密码忘记
  • ¥15 保护模式-系统加载-段寄存器