RE: Re[2]: [PHP] Re: Tom->Re: [PHP] session hijacking

2003-10-20 Thread Ow Mun Heng
>>The encryption happens server side and is really only intended to encrypt >>variables that are passed to web client such as product id and stuff. The only >>way to do secure login and prevent sniffing is to use ssl which will encrypt the >>traffic to and from the client. I suppose javascript coul

Re[2]: [PHP] Re: Tom->Re: [PHP] session hijacking

2003-10-20 Thread Tom Rogers
Hi, Tuesday, October 21, 2003, 12:52:33 PM, you wrote: OMH> Hi Tom, OMH> I've got a question for you regarding this encrypt class of yours.. Just OMH> wanted to understand how well it would work against a guy with a sniffer OMH> such as ethereal. (presuming he's on the LAN/wifi to access the app)