Its pretty secure. Adding more info and creating extra session is unnecessary overhead.
The best way to prevent this is to run session_regenerate_id(true).
[kireol explains everything nicely, I posted at the same time. Didn't see that post]
kkeith29
Nearly a Posting Virtuoso
1,357 posts since Jun 2007
Reputation Points: 235
Solved Threads: 194