View Single Post
Old 05-25-2006, 10:29 AM   #1 (permalink)
soma
Addict
 
soma's Avatar
 
Location: USA
[PHP] Using session_regenerate_id With Logins

On my login.php script, I'm trying to use the function session_regenerate_id to prevent session fixation attacks. Now, I'm a bit confused by all of this. On my login.php script, if the login validates, the following code runs:

Code:
session_start();
$_SESSION['username'] = $db_username;
I tried using the session_regenerate_id function, but when I add it to the above code, the session variable never sets itself. Strange...


Code:
session_start();
session_regenerate_id();
$_SESSION['username'] = $db_username;
I'm really lost.
__________________
Having Girl Problems?
soma is offline  
 

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73