Are sessions secure at all?..

Posted on 16th Feb 2014 by admin

I haven't really gotten into yet, but I was just thinking of something weird..

Lets say you have a session element $_SESSION['is_admin']..

Is that easy to modify the cookie or whatnot and change it to true? Or is it hashed or something weird or serverside.. I just never really thought about it before.

Other forums