3 ms·
How about checking the logged user's IP address on each page refresh and storing it on the server, and if there's more than one IP for the same user, invalidate
by adyus 15y ago
How about checking the logged user's IP address on each page refresh and storing it on the server, and if there's more than one IP for the same user, invalidate the session?
- espeed 15y agoYes, that's a good tactic and worth doing, but IP addresses can be spoofed.