If you use IP address for session cookie attacker can't use stolen cookie. However, you can't use IP address when BGP or Proxy are used. In this case the best protection is to change session cookie for each transaction using transaction counter. This will provide a transaction non-repudiation. If such session cookie is stolen and used by a hacker prior to a user, then user session will be blown away. Mike
This archive was generated by hypermail 2b30 : Fri Feb 01 2002 - 00:21:53 PST