Re: Session management.
| From: | Kelly Barrett | Date: | Wed, 14 Jun 2000 02:38:27 +0000 |
| Subject: | Re: Session management. | ||
| References: | 1 2 3 4 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-1806@lists.php.net to get a copy of this message | ||
> > > I'd make sure the random seed used on your server is truly valid.
Beyond
> > > that, you're far more likely to suffer some other attack besides a
> > > brute-force of the session management system, which would be painfully
> > > obvious in the logs in any case. If you are still worried about
guesses,
> > set
> > > a session variable with the user's User Agent and IP when the session
is
> > > created and check it on each page.
> >
> > You could also check that the referer (environment variable
HTTP_REFERER)
> > was from one of your own pages (by the domain) on every page where a
> session
> > should be valid, and kick them out if it doesn't checkout.
>
> This actually does absolutely nothing for security as the referrer
variable
> is set by the client and thus cannot be trusted in any way. The one way of
> making it useful would be to set a session variable using php_self and the
> check that the referer field matches the last page the user was at; I'd be
> surprised, however, if this didn't have unreliable interactions with the
> browser's cache.
Damn good point... And I'm sure thought of by any hacker who maybe trying to
hack a 32 digit hex number :)
Sorry, my mistake.... I was more thinking along the lines of a general user
going straight to page they shouldn't from their bookmarks or something, and
kicking back to a page they should be at, not as additional protection for
something thats hard to crack anyway.
Thanks for reminding me!
Kelly.