FRIHOST FORUMS SEARCH FAQ TOS BLOGS COMPETITIONS
You are invited to Log in or Register a free Frihost Account!


<?php session_start(); ?> on Every Page





Possum
Hi

The script that creates the pages for my site has a bug. It places <?php session_start(); ?> at the top of every page. I do need the <?php session_start(); ?> on some pages but not all..

Will this bug have adverse effects on my site security..

Cheers Possum
sonam
If you don't need on some pages then you can remove session_start from this pages and keep where you needed. How I know, for security session_start is not important like other part of script (user input, $_GET, etc.). Session_start activate session variables for each page, but, ones started sessions working in the background of site as long as browser is open.

Sonam

P.S.
BTW, ask some mod to move this in php forum where you will get more relevant answers. Wink
rvec
moved

I say just let those stay there. If you don't use sessions on those pages you won't change anything and thus it can't be a security problem.

Session data is also only known to the server and the client can only change/read it if there is a script on the server to do that. Session data is not send to the script by the user, but should be seen more like temporary data on the server.
Related topics
Reply to topic    Frihost Forum Index -> Scripting -> Php and MySQL

FRIHOST HOME | FAQ | TOS | ABOUT US | CONTACT US | SITE MAP
© 2005-2011 Frihost, forums powered by phpBB.