Loading...

使用.htaccess中更改session.name

Temperature: 0 °C

Mark ChangMark Chang
author_tools

session固定攻擊
session的默認名稱是PHPSESSID,此變量會保存在cookie中。
為了資訊安全,在.htaccess中以下行指令做更名的動作:

php_value session.name "SEESESSID"

以上紀錄~
 

More chapters / Next article: 直接在PHP重新命名帶有前綴的session.name

#故事  #PHPSESSID  #htaccess  #session固定攻擊  
https://innstory.com/story-使用htaccess中更改sessionname-2716

Prev
 htaccess_使用gzip壓縮網站加快加載速度並節省頻寬

Next
使用_htaccess_關閉緩存 

About the Author

Mark Chang

離不開電腦的宅男

Visitor message

Leave some footprints to prove that you visited me

Recommended reading

Author's other related stories

分享 CNNs Anthony Bourdain dead at 61

分享 CNNs Anthon...

難以置信,我還蠻喜歡看他的節目的。 或許....人都有過不去的坎,無論你是功成名就又或者是一事無成。...

codeing 像極了愛情

codeing 像極了愛情

codeing是一條不歸路。 除非你離去,否則你永遠都在修正你的code。 pexelsphoto5...

嘰嘰喳喳

嘰嘰喳喳

為什麼突然覺得iphone跟ie一樣討厭⊙⊙

Please select an option

error

Hi, thank you for your participation, but you cannot vote repeatedly~

Join innstory now and start recording your story.

"Innstory" is a place to store stories. We are committed to becoming a warm platform. Deepening the bonds between people is our direction.
We are convinced that the blockchain between people is not just a cold calculation. Join us now.

Wrong format