RE: [PHP-GENERAL] Session management.
| From: | Vikash Khatuwala | Date: | Mon, 22 May 2000 09:37:18 +0000 |
| Subject: | RE: [PHP-GENERAL] Session management. | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-274@lists.php.net to get a copy of this message | ||
I thought about using the ip address as an identifier but this adds a usability
problem because most of our users are using dynamic ip address connections and
if they disconnected in the middle of a session without logging out, they will
not be able to resume their session when they reconnect.
Is there a way around this?
Vikash.
>When i initiate a session I create a client fingerprint like this:
>
>function clientid($salt)
>{
> // Cnet
> $r_addr = getenv('REMOTE_ADDR');
> $id = substr($r_addr, 0, strrpos($r_addr, '.')+1);
> // Browser
> $id .= getenv('HTTP_USER_AGENT');
> // Domain
> $id .= $this->domain;
> // Encrypt (salted MD5)
> return crypt($id, '$1$'.$salt);
>}
>
>That i store in the session, and on every page a check to see if the client
>id exists. That way the hacker must be on the same ip cnet use the same
>browser and know the name of my session domain. The domain is just a name
>for the sites session since I have multiple sites on the same machin and a
>user with a valid session on site A shouldn´t be able to move to site B
>without getting a new session. Add a cookie to this and it´s quit good.
>
>> -----Original Message-----
>> From: Kari Asikainen [mailto:Kari.Asikainen@imnetti.fi]
>> Sent: Monday, May 22, 2000 11:03 AM
>> To: php-general@lists.php.net
>> Subject: RE: [PHP-GENERAL] Session management.
>>
>>
>> > I am looking for a mechanism that makes the sessions more secure.
>> > For example a hacker could try a url like mypage.php?PHPSESSID=
>> > dfc67bcf1d137cf599507b574a7f415c where this session id is
>> > something random that
>> > the hacker tries. If the site has several thousand hits per day
>> > then the hacker
>> > could get lucky and hit an active session and gain access.
>>
>> The cracker has "quite many" combinations to try so this
>> won't be a problem
>> :) And if you are writing an online bank or something else
>> that requires
>> very high level of security force the user to type his
>> password and check
>> it's validity from db before doing anything "important" ie.
>> ship an order
>> etc.
>>
>> -Kari
>>
>>
>> --
>> PHP General Mailing List (http://www.php.net/)
>> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
>> For additional commands, e-mail: php-general-help@lists.php.net
>> To contact the list administrators, e-mail:
>> php-list-admin@lists.php.net
>>
>
>--
>PHP General Mailing List (http://www.php.net/)
>To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
>For additional commands, e-mail: php-general-help@lists.php.net
>To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
Visit us at http://www.foodeasy.com