Re: Session management.
| From: | Damien Mc Kenna | Date: | Tue, 13 Jun 2000 15:06:24 +0000 |
| Subject: | Re: Session management. | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-1789@lists.php.net to get a copy of this message | ||
At 03:29 AM 5/22/00, you wrote:
> I am looking for a mechanism that makes the sessions more secure.
> For example a hacker could try a url like mypage.php?PHPSESSID=
> dfc67bcf1d137cf599507b574a7f415c where this session id is something
> random that the hacker tries. If the site has several thousand hits
> per day then the hacker could get lucky and hit an active session
> and gain access.
What you may want to do is do a check to ensure that the PHPSESSID
variable does not come from the URI, ie that it is only passed via
cookies. This however limits the functionality of PHP4's session
support.
Another idea would be to set PHP to only pass the session ID via
cookie. As a fall back, you could *manually* pass the ID via the
URI but change the variable name to something simple yet obscure,
like 'H=djhasfdsaf76sdafydsafwhatever', and then pass the value
back to the PHPSESSID on subsequent pages. A simpler way of
achieving this would be to change the name PHP uses for the variable
in the ini file to something obscure, which would take care of having
to do lots more code by hand.
Damien Mc Kenna, Computer Science Student, Married to Jen, Parent of 4 cats
http://mc-kenna.com - damien@mc-kenna.com - ICQ:17066133
Please use our new web and email addresses and remove any old ones you have
________________________________________________________
1stUp.com - Free the Web
Get your free Internet access at http://www.1stUp.com