Re: Session management.

From: Date: Tue, 13 Jun 2000 15:06:24 +0000
Subject: Re: Session management.
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-1789@lists.php.net to get a copy of this message
At 03:29 AM 5/22/00, you wrote: > I am looking for a mechanism that makes the sessions more secure. > For example a hacker could try a url like mypage.php?PHPSESSID= > dfc67bcf1d137cf599507b574a7f415c where this session id is something > random that the hacker tries. If the site has several thousand hits > per day then the hacker could get lucky and hit an active session > and gain access. What you may want to do is do a check to ensure that the PHPSESSID variable does not come from the URI, ie that it is only passed via cookies. This however limits the functionality of PHP4's session support. Another idea would be to set PHP to only pass the session ID via cookie. As a fall back, you could *manually* pass the ID via the URI but change the variable name to something simple yet obscure, like 'H=djhasfdsaf76sdafydsafwhatever', and then pass the value back to the PHPSESSID on subsequent pages. A simpler way of achieving this would be to change the name PHP uses for the variable in the ini file to something obscure, which would take care of having to do lots more code by hand. Damien Mc Kenna, Computer Science Student, Married to Jen, Parent of 4 cats http://mc-kenna.com - damien@mc-kenna.com - ICQ:17066133 Please use our new web and email addresses and remove any old ones you have ________________________________________________________ 1stUp.com - Free the Web Get your free Internet access at http://www.1stUp.com

« previous php.general (#1789) next »