RE: [PHP-GENERAL] Session management.
| From: | Gustafson, Mårten | Date: | Mon, 22 May 2000 09:36:51 +0000 |
| Subject: | RE: [PHP-GENERAL] Session management. | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-276@lists.php.net to get a copy of this message | ||
That´s why I use the c net. eg. if I´m on 212.31.54.1 when I log in the
clientid() function sets 212.31.54. so when/if my proxy/firewall changes my
ip adress it will still be valid.
--marten
> -----Original Message-----
> From: Vikash Khatuwala [mailto:vikash@foodeasy.com]
> Sent: Monday, May 22, 2000 11:37 AM
> To: Gustafson, Mårten
> Cc: php-general@lists.php.net
> Subject: RE: [PHP-GENERAL] Session management.
>
>
> I thought about using the ip address as an identifier but
> this adds a usability
> problem because most of our users are using dynamic ip
> address connections and
> if they disconnected in the middle of a session without
> logging out, they will
> not be able to resume their session when they reconnect.
>
> Is there a way around this?
>
> Vikash.
>
> >When i initiate a session I create a client fingerprint like this:
> >
> >function clientid($salt)
> >{
> > // Cnet
> > $r_addr = getenv('REMOTE_ADDR');
> > $id = substr($r_addr, 0, strrpos($r_addr, '.')+1);
> > // Browser
> > $id .= getenv('HTTP_USER_AGENT');
> > // Domain
> > $id .= $this->domain;
> > // Encrypt (salted MD5)
> > return crypt($id, '$1$'.$salt);
> >}
> >
> >That i store in the session, and on every page a check to
> see if the client
>
> >id exists. That way the hacker must be on the same ip cnet
> use the same
> >browser and know the name of my session domain. The domain
> is just a name
> >for the sites session since I have multiple sites on the
> same machin and a
>
> >user with a valid session on site A shouldn´t be able to
> move to site B
> >without getting a new session. Add a cookie to this and it´s
> quit good.
> >
> >> -----Original Message-----
> >> From: Kari Asikainen [mailto:Kari.Asikainen@imnetti.fi]
> >> Sent: Monday, May 22, 2000 11:03 AM
> >> To: php-general@lists.php.net
> >> Subject: RE: [PHP-GENERAL] Session management.
> >>
> >>
> >> > I am looking for a mechanism that makes the sessions more secure.
> >> > For example a hacker could try a url like mypage.php?PHPSESSID=
> >> > dfc67bcf1d137cf599507b574a7f415c where this session id is
> >> > something random that
> >> > the hacker tries. If the site has several thousand hits per day
> >> > then the hacker
> >> > could get lucky and hit an active session and gain access.
> >>
> >> The cracker has "quite many" combinations to try so this
> >> won't be a problem
> >> :) And if you are writing an online bank or something else
> >> that requires
> >> very high level of security force the user to type his
> >> password and check
> >> it's validity from db before doing anything "important" ie.
> >> ship an order
> >> etc.
> >>
> >> -Kari
> >>
> >>
> >> --
> >> PHP General Mailing List (http://www.php.net/)
> >> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> >> For additional commands, e-mail: php-general-help@lists.php.net
> >> To contact the list administrators, e-mail:
> >> php-list-admin@lists.php.net
> >>
> >
> >--
> >PHP General Mailing List (http://www.php.net/)
> >To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> >For additional commands, e-mail: php-general-help@lists.php.net
> >To contact the list administrators, e-mail:
> php-list-admin@lists.php.net
> >
> Visit us at http://www.foodeasy.com
>