douruduan8812 2013-07-19 12:10
浏览 31

只使用会话登录是否安全?

I have seen many scripts mixing sessions, with cookies and having two session names, the username or ID and the session ID.

Is this secure?:

    if ($this->login($username, $password))
    {
        // everything works..
        $_SESSION['name'] = $username;
    }

Why do you need to generate a new Session ID? Why mix cookies with it? and what are the best ways to do it to prevent most of the attacks?

  • 写回答

3条回答 默认 最新

  • dongqianzong4275 2013-07-19 12:17
    关注
    1. You generate session id's for each unique user so no data is shared!
    2. You use cookies to be able to use transparent sessions. So you don't have to pass the session id in every URL
    3. Read some of the comments in this thread
    评论

报告相同问题?

悬赏问题

  • ¥15 STM32无法向设备写入固件
  • ¥15 使用ESP8266连接阿里云出现问题
  • ¥15 BP神经网络控制倒立摆
  • ¥20 要这个数学建模编程的代码 并且能完整允许出来结果 完整的过程和数据的结果
  • ¥15 html5+css和javascript有人可以帮吗?图片要怎么插入代码里面啊
  • ¥30 Unity接入微信SDK 无法开启摄像头
  • ¥20 有偿 写代码 要用特定的软件anaconda 里的jvpyter 用python3写
  • ¥20 cad图纸,chx-3六轴码垛机器人
  • ¥15 移动摄像头专网需要解vlan
  • ¥20 access多表提取相同字段数据并合并