RE: [PHP] Re: session_destroy() but re-use session ID: security r isk?
| From: | Johnson, Kirk | Date: | Thu, 01 May 2003 17:09:57 +0000 |
| Subject: | RE: [PHP] Re: session_destroy() but re-use session ID: security r isk? | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-145986@lists.php.net to get a copy of this message | ||
Yes, the session ID is re-used, and a new, empty session file with the same
name is created. I believe session_start() will only result in a new session
ID being issued if the client didn't submit a cookie with an ID. In the
hypothetical example I gave, the client will send the cookie with an ID,
since a session cookie persists for the life of the browser instance.
> -----Original Message-----
> From: Bobby Patel [mailto:anup_patel@rogers.com]
> Sent: Thursday, May 01, 2003 10:49 AM
> To: php-general@lists.php.net
> Subject: [PHP] Re: session_destroy() but re-use session ID: security
> risk?
>
>
> It all depends on the session info saved on the server. But
> if you destroy
> the session data using session_destroy() then the next time the script
> starts with session_start(), it should issue a new session
> ID. Are you sure
> it gives the same session ID? if it does do this, for the script that
> terminates the session,
> <?php
> session_start();
> session_destroy();
> session_start(); # This will create a new session ID
> session_destroy();
> # instead of session_destroy(); I use this
> # setcookie(session_name(),"","","/");
> ?>
>
>
>
>
> "Kirk Johnson" <kjohnson@zootweb.com> wrote in message
> news:B11731D518B5D61183C700A0C98BE0D9FFC023@chef...
> > Say an application, using sessions, has a "logout" button
> which destroys
> the
> > session data. Say, also, that a user clicks that button,
> but then logs
> back
> > into the site without first closing their browser. Under these
> > circumstances, the session cookie and ID from their
> previous session will
> > get re-used for their new session. Is there any harm in this, from a
> > security viewpoint, or otherwise?
> >
> > TIA
> >
> > Kirk