Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

PHP Forum


You are currently viewing our PHP Forum as a guest. Please register to participate.
Login



Freelance Jobs

Reply
Old 11-23-2005, 06:31 AM Sessions help
-_darkranger_-'s Avatar
Super Talker

Posts: 122
Location: bolton...
Trades: 0
Well im making a community website and so far i think its okish but... i dont no much about sessions at all...

Im currently host my site on a friends server along with his test site...

I went on his test site, logged on, had a look around and then went onto my test site but it showed my username for my friends site and said i was logged in with it when i hadnt logged on my test site...

all i have when it comes to sessions on my site is session_start() and afew session vars i use for username, password and user level... is there any way i can make it so my site picks up only from my site and no elses :S im all confused please help...

btw if you want a look my site is here AphoticDreams

xx kieran xx

Last edited by -_darkranger_-; 11-23-2005 at 06:53 AM..
-_darkranger_- is offline
Reply With Quote
View Public Profile
 
 
Register now for full access!
Old 11-23-2005, 11:37 AM
funkdaddu's Avatar
Web Design Snob

Posts: 635
Trades: 0
give your username and password sessions different names than your buddies?

Last edited by funkdaddu; 11-23-2005 at 11:40 AM..
funkdaddu is offline
Reply With Quote
View Public Profile Visit funkdaddu's homepage!
 
Old 11-23-2005, 11:53 AM
-_darkranger_-'s Avatar
Super Talker

Posts: 122
Location: bolton...
Trades: 0
yea i guess but people could still set up a lil script to show all session vars... and then they could go onto my site and then onto the script they made and see all the session vars...

i just want something more secure + i dont really wanna spend AGES looking for all the session vars in my scripts to change the names of them

xx kieran xx
-_darkranger_- is offline
Reply With Quote
View Public Profile
 
Old 11-24-2005, 05:19 AM
ibbo's Avatar
Super Spam Talker

Posts: 880
Location: Leeds UK
Trades: 0
so make your sessions multidemensional I.E.

Code:
$_SESSION['site1']['username'] && $_SESSION['site1']['password']
$_SESSION['site2']['username'] && $_SESSION['site2']['password']
And your correct people could knock up a lil script but it will only show their session vars and nobody elses.

use a little imagination too.

If the session is set then they must have logged in already or you would not set their vars to $result->get_row().

And remember once you quit the browser your sessions will vanish.
Also look at cookies instead to allow cross site logins.

And finaly if your not prepared to edit your existing code then you should be doing a differnet job. I know a good coder is a lazy one but that does not mean you can get away with leaving your code and hoping for the best.

If they can break it they will!

Ibbo
__________________

Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE

Linux user #349545 :
(GNU/Linux)iD8DBQBAzWjX+MZAIjBWXGURAmflAKCntuBbuKCWenpm XoA7LNydllVQOwCf
ibbo is offline
Reply With Quote
View Public Profile Visit ibbo's homepage!
 
Old 12-21-2005, 09:53 AM tidbit
Novice Talker

Posts: 12
Trades: 0
Also, make sure that you are setting cookies on the client machine and compare the session to cookie on every page. this should eliminate anyone trying to read from another's session.
synapsex is offline
Reply With Quote
View Public Profile
 
Reply     « Reply to Sessions help
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.15530 seconds with 12 queries