Can session value be hacked?

后端 未结 7 1556
青春惊慌失措
青春惊慌失措 2020-12-05 19:05

When I came out of a site without logging out, next time i browse that site I found I am logged in there? How that server restore the session value for my browser? Is there

7条回答
  •  余生分开走
    2020-12-05 19:34

    Depending on whether the server checks the IP address trying to use the token (probably a cookie, but doesn't have to be) against the one that logged in, it might be possible for a thief to use that cookie to gain access to your account.

    A well-designed site will not only cause sessions to time-out but also restrict them to a single IP address (and browser user-agent, etc).

提交回复
热议问题