Re: [PROPOSAL] defense against session takeovers

From: Date: Fri, 01 Feb 2002 21:15:26 +0000
Subject: Re: [PROPOSAL] defense against session takeovers
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-78817@lists.php.net to get a copy of this message
> That is fine for a philosophy. I would still like to try to make > the default setup more secure. I agree, the least we can do is to > document this. > > How about that we use the SERVER_NAME environment variable when > generating session filenames? Instead of name like sess_XXXX, the name > could be sess_YYYY_XXXX, where YYYY is a server fingerprint? I > understand that this is not foolproof (say, for applications > that run on the same domain name) but it will solve the most > serious cases (shared hosting solutions). I really do think that someone setting up shared hosting should be clueful enough to configure things themselves or they probably shouldn't be in the business. -Rasmus

« previous php.dev (#78817) next »