Re: Session hijacking
| From: | John W. Holmes | Date: | Mon, 20 Oct 2003 02:29:17 +0000 |
| Subject: | Re: Session hijacking | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-166723@lists.php.net to get a copy of this message | ||
Chris Shiflett wrote:
For example, consider that a legitimate user clicks a link and goes to this URL: http://www.example.org/foo.php?PHPSESSID=12345 Perhaps the user has cookies disabled, so PHP appends the session identifier to the URL, or perhaps the developer does it automatically. Either way, what if a bad guy visits this URL: http://www.example.org/foo.php?PHPSESSID=12345Called session fixation. Here's good paper on this and how to deal with it. http://www.acros.si/papers/session_fixation.pdf The session_regenerate_id() function can come in handy here. -- ---John Holmes... Amazon Wishlist: www.amazon.com/o/registry/3BEXC84AB3A5E/ php|architect: The Magazine for PHP Professionals – www.phparch.com