RE: [PHP-GENERAL] Session management.

From: Date: Mon, 22 May 2000 09:37:18 +0000
Subject: RE: [PHP-GENERAL] Session management.
Groups: php.general 
Request: Send a blank email to php-general+get-274@lists.php.net to get a copy of this message
I thought about using the ip address as an identifier but this adds a usability problem because most of our users are using dynamic ip address connections and if they disconnected in the middle of a session without logging out, they will not be able to resume their session when they reconnect. Is there a way around this? Vikash. >When i initiate a session I create a client fingerprint like this: > >function clientid($salt) >{ > // Cnet > $r_addr = getenv('REMOTE_ADDR'); > $id = substr($r_addr, 0, strrpos($r_addr, '.')+1); > // Browser > $id .= getenv('HTTP_USER_AGENT'); > // Domain > $id .= $this->domain; > // Encrypt (salted MD5) > return crypt($id, '$1$'.$salt); >} > >That i store in the session, and on every page a check to see if the client >id exists. That way the hacker must be on the same ip cnet use the same >browser and know the name of my session domain. The domain is just a name >for the sites session since I have multiple sites on the same machin and a >user with a valid session on site A shouldn´t be able to move to site B >without getting a new session. Add a cookie to this and it´s quit good. > >> -----Original Message----- >> From: Kari Asikainen [mailto:Kari.Asikainen@imnetti.fi] >> Sent: Monday, May 22, 2000 11:03 AM >> To: php-general@lists.php.net >> Subject: RE: [PHP-GENERAL] Session management. >> >> >> > I am looking for a mechanism that makes the sessions more secure. >> > For example a hacker could try a url like mypage.php?PHPSESSID= >> > dfc67bcf1d137cf599507b574a7f415c where this session id is >> > something random that >> > the hacker tries. If the site has several thousand hits per day >> > then the hacker >> > could get lucky and hit an active session and gain access. >> >> The cracker has "quite many" combinations to try so this >> won't be a problem >> :) And if you are writing an online bank or something else >> that requires >> very high level of security force the user to type his >> password and check >> it's validity from db before doing anything "important" ie. >> ship an order >> etc. >> >> -Kari >> >> >> -- >> PHP General Mailing List (http://www.php.net/) >> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net >> For additional commands, e-mail: php-general-help@lists.php.net >> To contact the list administrators, e-mail: >> php-list-admin@lists.php.net >> > >-- >PHP General Mailing List (http://www.php.net/) >To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net >For additional commands, e-mail: php-general-help@lists.php.net >To contact the list administrators, e-mail: php-list-admin@lists.php.net > Visit us at http://www.foodeasy.com

« previous php.general (#274) next »