Re: Session hijacking

From: Date: Mon, 20 Oct 2003 01:45:45 +0000
Subject: Re: Session hijacking
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-166718@lists.php.net to get a copy of this message
Lots of great information in this thread as far as solutions go, but what I'm wondering is the concept behind how someone actually can hijack a session if register_globals is off. Should all this encryption and added protection be added to scripts with register_globals off and when steps are made to ensure (in a shared environment) that only your script can access the session files/db information? I seem to recall reading somewhere that a malicious user can manipulate cookies in a certain way to pass data directly into session variables, but the location I read this information escapes me. Any links or explanations would be much appreciated for designing security in future scripts. Thanks in advance. - Chris Wanstrath

« previous php.general (#166718) next »