If this is your first visit, be sure to
check out the FAQ by clicking the
link above. You may have to register
before you can post: click the register link above to proceed. To start viewing messages,
select the forum that you want to visit from the selection below.
Using $_SESSIONS/COOKIES? Maybe u shud read this first.
Alright. But is lava prodigits "based" then. Anyway i found a way thru lava sites, whether sid is in url or php session cookie. Only drawback, its browser dependent yo killer we cud run a test on ur site.
now thats a good looking web version.. one thing ive noticed, your using phpssid or cookies which kinda contradict with the one your recommending in this topic..
Im nt saying DONT use it, im showin u a hole. All u have to do is block the hole lol. Which brings us to the 2nd part of my thread. I have written a class that automatically validates every post form in my page to avoid noob csrf and i use one i got 4rm github to do ajax csrf protectn. Search "php csrf helper" in github to get anyone. And ffs pls avoid GET requests. NOTE: if u hav an XSS hole, u myt as well nt bother downloading d csrf helper.
Comment