Re: [PROPOSAL] defense against session takeovers

From: Date: Fri, 01 Feb 2002 21:24:16 +0000
Subject: Re: [PROPOSAL] defense against session takeovers
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-78818@lists.php.net to get a copy of this message
>   How about that we use the SERVER_NAME environment variable when
>   generating session filenames? Instead of name like sess_XXXX, the name
>   could be sess_YYYY_XXXX, where YYYY is a server fingerprint? I
>   understand that this is not foolproof (say, for applications
>   that run on the same domain name) but it will solve the most
>   serious cases (shared hosting solutions).

-1 for this because it destroys php functionality. it makes it impossible to
have multiple domains with the same sessions f.e.
www1.myserver.com
www2.myserver.com
news.myserver.com
archive.myserver.com
....




Thread (20 messages)

« previous php.dev (#78818) next »