Essential PHP Security: A Guide to Building Secure Web Applications by Chris Shiflett

Essential PHP Security: A Guide to Building Secure Web Applications by Chris Shiflett

Author:Chris Shiflett [Shiflett, Chris]
Language: eng
Format: azw3
Tags: COMPUTERS / Security / General
ISBN: 9780596104610
Publisher: O'Reilly Media
Published: 2005-10-13T04:00:00+00:00


Tip

Some experts warn against relying on the consistency of User-Agent. The concern is that an HTTP proxy in a cluster can modify User-Agent inconsistently with other proxies in the same cluster.

If you do not want to depend on User-Agent consistency, you can generate a random token:

<?php $token = md5(uniqid(rand(), TRUE)); $_SESSION['token'] = $token; ?>

This approach is slightly weaker, but it is much more reliable. Both methods provide a strong defense against session hijacking. The appropriate balance between security and reliability is up to you.



Download



Copyright Disclaimer:
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.