If someone managed to get hold of the moodle session id cookie for a recently started moodle session, what further checks are there to stop them hijacking the session?
I see IP address is recorded in the log table so this might be one further check, but can this be matched with the session id, particularly if sessions are being recorded in flat files on the server rather than in the database?