RE: [PHP-GENERAL] Session management.
| From: | Gustafson, Mårten | Date: | Mon, 22 May 2000 09:07:38 +0000 |
| Subject: | RE: [PHP-GENERAL] Session management. | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-273@lists.php.net to get a copy of this message | ||
When i initiate a session I create a client fingerprint like this:
function clientid($salt)
{
// Cnet
$r_addr = getenv('REMOTE_ADDR');
$id = substr($r_addr, 0, strrpos($r_addr, '.')+1);
// Browser
$id .= getenv('HTTP_USER_AGENT');
// Domain
$id .= $this->domain;
// Encrypt (salted MD5)
return crypt($id, '$1$'.$salt);
}
That i store in the session, and on every page a check to see if the client
id exists. That way the hacker must be on the same ip cnet use the same
browser and know the name of my session domain. The domain is just a name
for the sites session since I have multiple sites on the same machin and a
user with a valid session on site A shouldn´t be able to move to site B
without getting a new session. Add a cookie to this and it´s quit good.
> -----Original Message-----
> From: Kari Asikainen [mailto:Kari.Asikainen@imnetti.fi]
> Sent: Monday, May 22, 2000 11:03 AM
> To: php-general@lists.php.net
> Subject: RE: [PHP-GENERAL] Session management.
>
>
> > I am looking for a mechanism that makes the sessions more secure.
> > For example a hacker could try a url like mypage.php?PHPSESSID=
> > dfc67bcf1d137cf599507b574a7f415c where this session id is
> > something random that
> > the hacker tries. If the site has several thousand hits per day
> > then the hacker
> > could get lucky and hit an active session and gain access.
>
> The cracker has "quite many" combinations to try so this
> won't be a problem
> :) And if you are writing an online bank or something else
> that requires
> very high level of security force the user to type his
> password and check
> it's validity from db before doing anything "important" ie.
> ship an order
> etc.
>
> -Kari
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail:
> php-list-admin@lists.php.net
>