Re: Session management.
| From: | Chris Adams | Date: | Wed, 14 Jun 2000 02:49:29 +0000 |
| Subject: | Re: Session management. | ||
| References: | 1 2 3 4 5 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-1808@lists.php.net to get a copy of this message | ||
> > > You could also check that the referer (environment variable
> HTTP_REFERER)
> > > was from one of your own pages (by the domain) on every page where a
> > session
> > > should be valid, and kick them out if it doesn't checkout.
> >
> > This actually does absolutely nothing for security as the referrer
> variable
> > is set by the client and thus cannot be trusted in any way. The one way
of
> > making it useful would be to set a session variable using php_self and
the
> > check that the referer field matches the last page the user was at; I'd
be
> > surprised, however, if this didn't have unreliable interactions with the
> > browser's cache.
>
> Damn good point... And I'm sure thought of by any hacker who maybe trying
to
> hack a 32 digit hex number :)
>
> Sorry, my mistake.... I was more thinking along the lines of a general
user
> going straight to page they shouldn't from their bookmarks or something,
and
> kicking back to a page they should be at, not as additional protection for
> something thats hard to crack anyway.
I recommend subscribing to a few lists like BUGTRAQ if you regularly write
code that needs to be secure. The first few weeks is usually quite
enlightening as to the creativity and perseverance some attackers bring.
Complete paranoia is a very reasonable mindset for a security system
developer or admin.