Re: [PROPOSAL] defense against session takeovers
| From: | Rasmus Lerdorf | Date: | Fri, 01 Feb 2002 21:15:26 +0000 |
| Subject: | Re: [PROPOSAL] defense against session takeovers | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-78817@lists.php.net to get a copy of this message | ||
> That is fine for a philosophy. I would still like to try to make
> the default setup more secure. I agree, the least we can do is to
> document this.
>
> How about that we use the SERVER_NAME environment variable when
> generating session filenames? Instead of name like sess_XXXX, the name
> could be sess_YYYY_XXXX, where YYYY is a server fingerprint? I
> understand that this is not foolproof (say, for applications
> that run on the same domain name) but it will solve the most
> serious cases (shared hosting solutions).
I really do think that someone setting up shared hosting should be clueful
enough to configure things themselves or they probably shouldn't be in the
business.
-Rasmus