If you must work with a PHP Session-ID, sometimes it is better to check if these Session-ID is valid.
/** * Checks a Session-ID * * @author Thomas Deuling <tdeuling@gmail.com> * @param string $sessionID Session-ID * @return boolean Is valid?! */ function checkSessionID($sessionID="") { return !preg_match('/^[a-zA-Z0-9]{26}$/', $sessionID); }