Session management.
| From: | Vikash Khatuwala | Date: | Mon, 22 May 2000 07:29:44 +0000 |
| Subject: | Session management. | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-268@lists.php.net to get a copy of this message | ||
Hi,
Thanks for your reply.
>session_start(); // get all the stuff
>if(time() > ($time + 3600)) // check if inactive for
>an hour
>{ // if yes then blow the session and print the stuff
>session_destroy(); // blow
>echo "You need to <a href=login.php>re-login</a>";
>exit;
>}
This will check to see if the session has expired.
I am looking for a mechanism that makes the sessions more secure.
For example a hacker could try a url like mypage.php?PHPSESSID=
dfc67bcf1d137cf599507b574a7f415c where this session id is something random that
the hacker tries. If the site has several thousand hits per day then the hacker
could get lucky and hit an active session and gain access.
>> is still kept. I want destroy the cookie so that
>> when the user logs in again
>> before the cookie times out, they will get a new
>> session id.
>
>You don't need to do this... the session id is now
>rotten.. and can't be used... though i'm not sure..
>
I agree that this is not necessary but would be a nice thing if php automatically
destroyed the cookie. Anyway I am most interested in a way that will check at
every step during his session to make sure that the person who is access a userpage
is the same person who logged in.
As yet I havnt been able to find any good resources on doing session management
securly.
Thanks,
Vikash.
Visit us at http://www.foodeasy.com