05-25-2006, 10:29 AM | #1 (permalink) |
Addict
Location: USA
|
[PHP] Using session_regenerate_id With Logins
On my login.php script, I'm trying to use the function session_regenerate_id to prevent session fixation attacks. Now, I'm a bit confused by all of this. On my login.php script, if the login validates, the following code runs:
Code:
session_start(); $_SESSION['username'] = $db_username; Code:
session_start(); session_regenerate_id(); $_SESSION['username'] = $db_username;
__________________
Having Girl Problems? |
Tags |
logins, php, sessionregenerateid |
|
|