Restrict session to IP 

Hint  Go to the PHP My Admin challenge

You should use ssl

Subdomain should be listed in SSL certificate
