Re: Session management.
| From: | Kelly Barrett | Date: | Wed, 14 Jun 2000 02:24:45 +0000 |
| Subject: | Re: Session management. | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-1803@lists.php.net to get a copy of this message | ||
> At 03:29 AM 5/22/00, you wrote:
> > I am looking for a mechanism that makes the sessions more secure.
> > For example a hacker could try a url like mypage.php?PHPSESSID=
> > dfc67bcf1d137cf599507b574a7f415c where this session id is something
> > random that the hacker tries. If the site has several thousand hits
> > per day then the hacker could get lucky and hit an active session
> > and gain access.
>
> I'd check the math before worrying much about this. The session ids use 32
> hexadecimal digits. The risk of someone guessing a correct session out of
> 16^32 possibilities are almost certainly lower than the chances of having
> some easier to exploit vulnerability.
>
> You have 340,282,366,920,938,000,000,000,000,000,000,000,000 choices.
> Assuming that you have 3,000,000 active sessions, that still leaves
> 113,427,455,640,313,000,000,000,000,000,000 invalid combinations for every
> valid one.
>
> I'd make sure the random seed used on your server is truly valid. Beyond
> that, you're far more likely to suffer some other attack besides a
> brute-force of the session management system, which would be painfully
> obvious in the logs in any case. If you are still worried about guesses,
set
> a session variable with the user's User Agent and IP when the session is
> created and check it on each page.
You could also check that the referer (environment variable HTTP_REFERER)
was from one of your own pages (by the domain) on every page where a session
should be valid, and kick them out if it doesn't checkout.
Cheers,
Kelly.