Preventing session hijacking and forgery attacks

  • Regenerating session IDs
    .
  • Providing a logout option
    .
  • Keeping sessions short
    .
  • Do not rely solely on session ID
    .
 


+ o -