You could as well generate a unique Hash for the mashine accessing stats,
but that would be killing a fly with a rock.
Verifying IP together with the session, is actually very secure.
Chances of picking up a valid session-ID that lasts an hour, or 30 minutes
created by a user of the same proxy-IP is rather unlikely.
but that would be killing a fly with a rock.
Verifying IP together with the session, is actually very secure.
Chances of picking up a valid session-ID that lasts an hour, or 30 minutes
created by a user of the same proxy-IP is rather unlikely.






Comment