DEV Community

Discussion on: Understanding Cookies and Sessions in PHP

Collapse
 
suckup_de profile image
Lars Moelleken

"Sessions cannot be accessed by hackers since it stores user in the server".

⇐ This is only valid if you protect your PHPSESSID Cookie. Every developer should try this: login into a PHP bases web application and copy and past the cookie into a different Browser, mostly you will be logged-in into your account without any password