Prevent session cookie hijacking WITHOUT SSL
问题 To prevent session hijacking, i tried to assign a specific cookie name to each user based on these variables: User-agent and IP Address . I have used following function to generate session cookie name which holds session ID . static function getSessionName(){ $id= @md5(base64_encode(self::$secretToken.$_SERVER["HTTP_USER_AGENT"].$_SERVER["REMOTE_ADDR"])); while(is_numeric($id{0})){ $id = substr($id, 1).$id{0}; } return $id; } It means that every user which visits my website, will have a