3 ms·
One trick I read while writing some session code is to generate a session fingerprint using a salted md5 of the IP address + the User-Agent. That adds one extr
by dstein 15y ago
One trick I read while writing some session code is to generate a session fingerprint using a salted md5 of the IP address + the User-Agent. That adds one extra level of protection in case your session storage (but not your webserver) is comprimised. If an attacker can spoof IP's, and knows the user-agents, then there is no safety except SSL. A post-modern alternative would be to open a websocket and do all communication through it.
See http://stackoverflow.com/questions/616545/php-sessions-useragent-with-salt http://stackoverflow.com/questions/616545/php-sessions-usera...