Re: trans-sid warning?

From: Date: Sun, 18 Aug 2002 17:52:08 +0000
Subject: Re: trans-sid warning?
Groups: php.dev 
Request: Send a blank email to php-dev+get-87015@lists.php.net to get a copy of this message
>> But the real issue here is about session hijacking. Yes, of course >> people can send whatever session id they want to PHP. Since the >> session id comes from the user we need to accept what is sent. > > This is what I consider unconceivable. > Why ever should tickets issued by the user be accepted, to what pro? > Something clashes here with that 'very umpredictable dedicated device'. > I'd prefer no acceptance of user provided id, if not where expressely > configured. There is a simple solution, make sure your the one generating the IDs, and upon each "proper" session start (where no session id is passed in) set a session "I started this session" variable. If a session ID has been passed in, then check for that variable, if it exists - continue, if not then show an error message. Note: you will experiance the same problem if the session times out. -- Dan Hardiker [dhardiker@staff.firstcreative.net] ADAM Software & Systems Engineer First Creative Ltd

« previous php.dev (#87015) next »