Re: Session management.

From: Date: Wed, 14 Jun 2000 02:38:27 +0000
Subject: Re: Session management.
References: 1 2 3 4  Groups: php.general 
Request: Send a blank email to php-general+get-1806@lists.php.net to get a copy of this message
> > > I'd make sure the random seed used on your server is truly valid. Beyond > > > that, you're far more likely to suffer some other attack besides a > > > brute-force of the session management system, which would be painfully > > > obvious in the logs in any case. If you are still worried about guesses, > > set > > > a session variable with the user's User Agent and IP when the session is > > > created and check it on each page. > > > > You could also check that the referer (environment variable HTTP_REFERER) > > was from one of your own pages (by the domain) on every page where a > session > > should be valid, and kick them out if it doesn't checkout. > > This actually does absolutely nothing for security as the referrer variable > is set by the client and thus cannot be trusted in any way. The one way of > making it useful would be to set a session variable using php_self and the > check that the referer field matches the last page the user was at; I'd be > surprised, however, if this didn't have unreliable interactions with the > browser's cache. Damn good point... And I'm sure thought of by any hacker who maybe trying to hack a 32 digit hex number :) Sorry, my mistake.... I was more thinking along the lines of a general user going straight to page they shouldn't from their bookmarks or something, and kicking back to a page they should be at, not as additional protection for something thats hard to crack anyway. Thanks for reminding me! Kelly.

« previous php.general (#1806) next »