Re: [PROPOSAL] defense against session takeovers
| From: | Ivan Ristic | Date: | Fri, 01 Feb 2002 21:12:40 +0000 |
| Subject: | Re: [PROPOSAL] defense against session takeovers | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-78816@lists.php.net to get a copy of this message | ||
> The general philosophy of PHP has always been to make PHP easy for the
> beginner yet flexible enough for advanced users. This fits that rule.
> Give the advanced users the tools to configure PHP to have per-virtualhost
> session handling, while sessions still work for the guy who just installed
> PHP on his own little server and really doesn't know what he is doing.
That is fine for a philosophy. I would still like to try to make
the default setup more secure. I agree, the least we can do is to
document this.
How about that we use the SERVER_NAME environment variable when
generating session filenames? Instead of name like sess_XXXX, the name
could be sess_YYYY_XXXX, where YYYY is a server fingerprint? I
understand that this is not foolproof (say, for applications
that run on the same domain name) but it will solve the most
serious cases (shared hosting solutions).
--
Ivan Ristic, ivan.ristic@iname.com
[ Weblog on PHP, Software development, Intranets,
and Knowledge Management: http://www.webkreator.com ]