Re: Session management.
| From: | Chris Adams | Date: | Wed, 14 Jun 2000 02:26:09 +0000 |
| Subject: | Re: Session management. | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-1805@lists.php.net to get a copy of this message | ||
> > I'd make sure the random seed used on your server is truly valid. Beyond
> > that, you're far more likely to suffer some other attack besides a
> > brute-force of the session management system, which would be painfully
> > obvious in the logs in any case. If you are still worried about guesses,
> set
> > a session variable with the user's User Agent and IP when the session is
> > created and check it on each page.
>
> You could also check that the referer (environment variable HTTP_REFERER)
> was from one of your own pages (by the domain) on every page where a
session
> should be valid, and kick them out if it doesn't checkout.
This actually does absolutely nothing for security as the referrer variable
is set by the client and thus cannot be trusted in any way. The one way of
making it useful would be to set a session variable using php_self and the
check that the referer field matches the last page the user was at; I'd be
surprised, however, if this didn't have unreliable interactions with the
browser's cache.