So everyone says that sessions have security risks, I want to know what kind of risks are these? What can hackers do with sessions?
This is not about knowing how to avoid attacks, I want to know how hackers are doing it, and what are they doing.
I talk about PHP SESSIONS.
Mainly here are the risks:
Consider using OWASP to do against it.
Also have a look at:
PHP Security Guide