Files
build-web-application-with-…/6.4.md
2012-09-24 14:43:18 +08:00

18 lines
678 B
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
#6.4 预防session劫持
session劫持是一种比较严重的安全威胁也是一种广泛存在的威胁在session技术中客户端和服务端通过传送session的标识符来维护会话但这个标识符很容易就能被嗅探到从而被其他人利用这属于一种中间人攻击。
本部分通过一个实例来说明何为会话劫持通过这个实例读者其实更能理解session的本质。
##session劫持过程
##session劫持防范
###cookieonly和token
###间隔生成新的SID
## links
* [目录](<preface.md>)
* 上一节: [session存储](<6.3.md>)
* 下一节: [小结](<6.5.md>)
## LastModified
* $Id$