if (!isset( $_SESSION [ 'user_agent' ])){ |
$_SESSION [ 'user_agent' ] = $_SERVER [ 'REMOTE_ADDR' ]. $_SERVER [ 'HTTP_USER_AGENT' ]; |
} |
/* 如果用户session ID是伪造 */ |
elseif ( $_SESSION [ 'user_agent' ] != $_SERVER [ 'REMOTE_ADDR' ] . $_SERVER [ 'HTTP_USER_AGENT' ]) { |
session_regenerate_id(); |
} |