Re: Re: Session Security: Selectively Disable CHECK_SESSION_ADDR
"Mike Orr" <[email protected]>
| Newsgroups | gmane.comp.web.quixote.user |
|---|---|
| Message-ID | <[email protected]> |
On 6/29/06, Charles <[email protected]> wrote: > Primarily session id cookie hijacking... TurboGears signs the cookie using a hash. I don't understand how this works, and the developer said he only did it because people insisted, not because he thought it was more secure. But I can dig up the notes and implementation if there's sufficient interest. -- Mike Orr <[email protected]>