View Single Post
Old 03-19-2004, 11:32 AM  
AnalProbe
pain in the Ass
 
AnalProbe's Avatar
 
Industry Role:
Join Date: Jan 2004
Posts: 3,727
Quote:
Originally posted by Big E
The only problem with sessions is that the underlying content (images, videos etc) are still accessible. Sessions only protect HTML/PHP files.

Sure, you can put HTTP_REFERER protection in, but we all know how easy it is to spoof referrers.

Fortunately, there's a solution to this.

Addition: SSL is *NOT* the solution. It's very CPI-intensive.. if you're doing ANY kind of traffic, you're going to be bogged down, even if you've got an SSL accelerator card.
As I stated before :

You only use the SSL for the login screen...


PHP sessions can be made 100% secure, yes.

Not only HTML files, you can show your pics like pic.php?pic=123
AnalProbe is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote