RE: [PHP-GENERAL] Session management.

From: Date: Mon, 22 May 2000 09:36:51 +0000
Subject: RE: [PHP-GENERAL] Session management.
Groups: php.general 
Request: Send a blank email to php-general+get-276@lists.php.net to get a copy of this message
That´s why I use the c net. eg. if I´m on 212.31.54.1 when I log in the clientid() function sets 212.31.54. so when/if my proxy/firewall changes my ip adress it will still be valid. --marten > -----Original Message----- > From: Vikash Khatuwala [mailto:vikash@foodeasy.com] > Sent: Monday, May 22, 2000 11:37 AM > To: Gustafson, Mårten > Cc: php-general@lists.php.net > Subject: RE: [PHP-GENERAL] Session management. > > > I thought about using the ip address as an identifier but > this adds a usability > problem because most of our users are using dynamic ip > address connections and > if they disconnected in the middle of a session without > logging out, they will > not be able to resume their session when they reconnect. > > Is there a way around this? > > Vikash. > > >When i initiate a session I create a client fingerprint like this: > > > >function clientid($salt) > >{ > > // Cnet > > $r_addr = getenv('REMOTE_ADDR'); > > $id = substr($r_addr, 0, strrpos($r_addr, '.')+1); > > // Browser > > $id .= getenv('HTTP_USER_AGENT'); > > // Domain > > $id .= $this->domain; > > // Encrypt (salted MD5) > > return crypt($id, '$1$'.$salt); > >} > > > >That i store in the session, and on every page a check to > see if the client > > >id exists. That way the hacker must be on the same ip cnet > use the same > >browser and know the name of my session domain. The domain > is just a name > >for the sites session since I have multiple sites on the > same machin and a > > >user with a valid session on site A shouldn´t be able to > move to site B > >without getting a new session. Add a cookie to this and it´s > quit good. > > > >> -----Original Message----- > >> From: Kari Asikainen [mailto:Kari.Asikainen@imnetti.fi] > >> Sent: Monday, May 22, 2000 11:03 AM > >> To: php-general@lists.php.net > >> Subject: RE: [PHP-GENERAL] Session management. > >> > >> > >> > I am looking for a mechanism that makes the sessions more secure. > >> > For example a hacker could try a url like mypage.php?PHPSESSID= > >> > dfc67bcf1d137cf599507b574a7f415c where this session id is > >> > something random that > >> > the hacker tries. If the site has several thousand hits per day > >> > then the hacker > >> > could get lucky and hit an active session and gain access. > >> > >> The cracker has "quite many" combinations to try so this > >> won't be a problem > >> :) And if you are writing an online bank or something else > >> that requires > >> very high level of security force the user to type his > >> password and check > >> it's validity from db before doing anything "important" ie. > >> ship an order > >> etc. > >> > >> -Kari > >> > >> > >> -- > >> PHP General Mailing List (http://www.php.net/) > >> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > >> For additional commands, e-mail: php-general-help@lists.php.net > >> To contact the list administrators, e-mail: > >> php-list-admin@lists.php.net > >> > > > >-- > >PHP General Mailing List (http://www.php.net/) > >To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > >For additional commands, e-mail: php-general-help@lists.php.net > >To contact the list administrators, e-mail: > php-list-admin@lists.php.net > > > Visit us at http://www.foodeasy.com >

« previous php.general (#276) next »