Re: Session management.

From: Date: Wed, 14 Jun 2000 02:24:45 +0000
Subject: Re: Session management.
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-1803@lists.php.net to get a copy of this message
> At 03:29 AM 5/22/00, you wrote: > > I am looking for a mechanism that makes the sessions more secure. > > For example a hacker could try a url like mypage.php?PHPSESSID= > > dfc67bcf1d137cf599507b574a7f415c where this session id is something > > random that the hacker tries. If the site has several thousand hits > > per day then the hacker could get lucky and hit an active session > > and gain access. > > I'd check the math before worrying much about this. The session ids use 32 > hexadecimal digits. The risk of someone guessing a correct session out of > 16^32 possibilities are almost certainly lower than the chances of having > some easier to exploit vulnerability. > > You have 340,282,366,920,938,000,000,000,000,000,000,000,000 choices. > Assuming that you have 3,000,000 active sessions, that still leaves > 113,427,455,640,313,000,000,000,000,000,000 invalid combinations for every > valid one. > > I'd make sure the random seed used on your server is truly valid. Beyond > that, you're far more likely to suffer some other attack besides a > brute-force of the session management system, which would be painfully > obvious in the logs in any case. If you are still worried about guesses, set > a session variable with the user's User Agent and IP when the session is > created and check it on each page. You could also check that the referer (environment variable HTTP_REFERER) was from one of your own pages (by the domain) on every page where a session should be valid, and kick them out if it doesn't checkout. Cheers, Kelly.

« previous php.general (#1803) next »