Loading...

使用.htaccess中更改session.name

Temperature: 0 °C

Mark ChangMark Chang
author_tools

session固定攻擊
session的默認名稱是PHPSESSID,此變量會保存在cookie中。
為了資訊安全,在.htaccess中以下行指令做更名的動作:

php_value session.name "SEESESSID"

以上紀錄~
 

More chapters / Next article: 直接在PHP重新命名帶有前綴的session.name

#故事  #PHPSESSID  #htaccess  #session固定攻擊  
https://innstory.com/story-使用htaccess中更改sessionname-2716

Prev
 htaccess_使用gzip壓縮網站加快加載速度並節省頻寬

Next
使用_htaccess_關閉緩存 

About the Author

Mark Chang

離不開電腦的宅男

Visitor message

Leave some footprints to prove that you visited me

Recommended reading

Author's other related stories

嘰嘰喳喳

嘰嘰喳喳

我們總是在世人面前假裝自己以為的瀟灑。 卻過不了自己在心裏築起的高牆。

synology nas 上如何解決Fatal error: Call to undefined function exif_read_data()

synology nas 上...

在synology nas執行PHP時發生以下錯誤 PHP 致命錯誤:調用未定義函數 exifrea...

分享 人事動盪!近400天GoogleCloud旅程告終台灣區總經理邵光華低調卸任|數位時代

分享 人事動盪!近400天G...

其實新聞裡沒有提動任何關於hp的關鍵字,但我在畫面中卻只看到hp。 #hp螢幕

Please select an option

error

Hi, thank you for your participation, but you cannot vote repeatedly~

Join innstory now and start recording your story.

"Innstory" is a place to store stories. We are committed to becoming a warm platform. Deepening the bonds between people is our direction.
We are convinced that the blockchain between people is not just a cold calculation. Join us now.

Wrong format