Re: Session management.
| From: | Chris Adams | Date: | Wed, 14 Jun 2000 01:50:37 +0000 |
| Subject: | Re: Session management. | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-1799@lists.php.net to get a copy of this message | ||
At 03:29 AM 5/22/00, you wrote:
> I am looking for a mechanism that makes the sessions more secure.
> For example a hacker could try a url like mypage.php?PHPSESSID=
> dfc67bcf1d137cf599507b574a7f415c where this session id is something
> random that the hacker tries. If the site has several thousand hits
> per day then the hacker could get lucky and hit an active session
> and gain access.
I'd check the math before worrying much about this. The session ids use 32
hexadecimal digits. The risk of someone guessing a correct session out of
16^32 possibilities are almost certainly lower than the chances of having
some easier to exploit vulnerability.
You have 340,282,366,920,938,000,000,000,000,000,000,000,000 choices.
Assuming that you have 3,000,000 active sessions, that still leaves
113,427,455,640,313,000,000,000,000,000,000 invalid combinations for every
valid one.
I'd make sure the random seed used on your server is truly valid. Beyond
that, you're far more likely to suffer some other attack besides a
brute-force of the session management system, which would be painfully
obvious in the logs in any case. If you are still worried about guesses, set
a session variable with the user's User Agent and IP when the session is
created and check it on each page.