View Single Post
Old 03-13-2005, 04:45 PM  
mrthumbs
salad tossing sig guy
 
mrthumbs's Avatar
 
Join Date: Apr 2002
Location: mrthumbs*gmail.com
Posts: 11,702
Quote:
Originally Posted by Varius
Someone just suggested to me verifying the IP is the same as the one when the session got created, which I think is a good idea for extra security and we will implement.

what about simply not putting session id's in url ;)
mrthumbs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote