Developing a secure PHP login and authentication strategy

前端 未结 8 1592
借酒劲吻你
借酒劲吻你 2020-12-13 03:05

I\'m developing a login and authentication system for a new PHP site and have been reading up on the various attacks and vulnerabilities. However, it\'s a bit confusing, so

8条回答
  •  北荒
    北荒 (楼主)
    2020-12-13 03:56

    Most sites just use the PHP session; the session data ($_SESSION) is in a file on your server. All that's sent to the browser is a session ID. Be sure to regenerate the session each request (session_regenerate_id). You don't need to be sending two cookies or anything.

    This is less vulnerable to session hijacking as every request is a new ID, so an old one intercepted by an attacker is useless.

    The best solution, obviously, would be to use SSL throughout the entire session.

提交回复
热议问题