A lot of people will use sessions with some type of MD5 hash of the user information and password as well (in cookies or urls) this way it makes it way harder to fake sessions, and yes sessions can be faked depending on how they are implemented. Many session handlers forget that a substantial portion of the internet (AOL many other ISPS) connect though transparent proxies which makes the originating IP almost worthless in the session state.