Notes on PHP Session Security

Harry Fuecks‘ notes on PHP session security:

„[…] things to watch out for when using sessions for your sites login system;

    1. Shared web servers
    1. XSS exploits
    1. Session IDs in URL
    1. Session Fixation
    1. Sniffing Packets
    1. Cookies are not for session data“