Re: Session management.

From: Date: Wed, 14 Jun 2000 01:50:37 +0000
Subject: Re: Session management.
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-1799@lists.php.net to get a copy of this message
At 03:29 AM 5/22/00, you wrote: > I am looking for a mechanism that makes the sessions more secure. > For example a hacker could try a url like mypage.php?PHPSESSID= > dfc67bcf1d137cf599507b574a7f415c where this session id is something > random that the hacker tries. If the site has several thousand hits > per day then the hacker could get lucky and hit an active session > and gain access. I'd check the math before worrying much about this. The session ids use 32 hexadecimal digits. The risk of someone guessing a correct session out of 16^32 possibilities are almost certainly lower than the chances of having some easier to exploit vulnerability. You have 340,282,366,920,938,000,000,000,000,000,000,000,000 choices. Assuming that you have 3,000,000 active sessions, that still leaves 113,427,455,640,313,000,000,000,000,000,000 invalid combinations for every valid one. I'd make sure the random seed used on your server is truly valid. Beyond that, you're far more likely to suffer some other attack besides a brute-force of the session management system, which would be painfully obvious in the logs in any case. If you are still worried about guesses, set a session variable with the user's User Agent and IP when the session is created and check it on each page.

« previous php.general (#1799) next »