RE: [PHP] Re: session_destroy() but re-use session ID: security r isk?

From: Date: Thu, 01 May 2003 17:09:57 +0000
Subject: RE: [PHP] Re: session_destroy() but re-use session ID: security r isk?
Groups: php.general 
Request: Send a blank email to php-general+get-145986@lists.php.net to get a copy of this message
Yes, the session ID is re-used, and a new, empty session file with the same name is created. I believe session_start() will only result in a new session ID being issued if the client didn't submit a cookie with an ID. In the hypothetical example I gave, the client will send the cookie with an ID, since a session cookie persists for the life of the browser instance. > -----Original Message----- > From: Bobby Patel [mailto:anup_patel@rogers.com] > Sent: Thursday, May 01, 2003 10:49 AM > To: php-general@lists.php.net > Subject: [PHP] Re: session_destroy() but re-use session ID: security > risk? > > > It all depends on the session info saved on the server. But > if you destroy > the session data using session_destroy() then the next time the script > starts with session_start(), it should issue a new session > ID. Are you sure > it gives the same session ID? if it does do this, for the script that > terminates the session, > <?php > session_start(); > session_destroy(); > session_start(); # This will create a new session ID > session_destroy(); > # instead of session_destroy(); I use this > # setcookie(session_name(),"","","/"); > ?> > > > > > "Kirk Johnson" <kjohnson@zootweb.com> wrote in message > news:B11731D518B5D61183C700A0C98BE0D9FFC023@chef... > > Say an application, using sessions, has a "logout" button > which destroys > the > > session data. Say, also, that a user clicks that button, > but then logs > back > > into the site without first closing their browser. Under these > > circumstances, the session cookie and ID from their > previous session will > > get re-used for their new session. Is there any harm in this, from a > > security viewpoint, or otherwise? > > > > TIA > > > > Kirk

« previous php.general (#145986) next »