duanduan1993 2012-08-21 23:52
浏览 25

是否有即用型会话劫持保护API?

I have looked into many threads that discuss preventing Session hijacking & fixation but I feel that there are always details I'm missing out.

What I'm looking for is something with the same principle as what HTML Purifier does against XSS, but in this case against Session hijacking and fixation.

Is there an API or a PHP class made by anyone that covers everything that can be done to prevent Session Hijacking and Fixation?

Or is it better to do it on my own?

Thanks in advance. Regards

  • 写回答

3条回答 默认 最新

  • dseslyh6662605 2012-08-22 01:12
    关注

    It is always better to make one yourself. It might be harder and in the end not do much, but frameworks and APIs are accessible from those guys who will make the high-jacking.

    Try encrypting your sessions and working that way. Security requires drastic changes to the architecture of a platform and consequently of its database

    评论

报告相同问题?

悬赏问题

  • ¥15 Vue3 大型图片数据拖动排序
  • ¥15 划分vlan后不通了
  • ¥15 GDI处理通道视频时总是带有白色锯齿
  • ¥20 用雷电模拟器安装百达屋apk一直闪退
  • ¥15 算能科技20240506咨询(拒绝大模型回答)
  • ¥15 自适应 AR 模型 参数估计Matlab程序
  • ¥100 角动量包络面如何用MATLAB绘制
  • ¥15 merge函数占用内存过大
  • ¥15 使用EMD去噪处理RML2016数据集时候的原理
  • ¥15 神经网络预测均方误差很小 但是图像上看着差别太大