Re: sessions and security

From: Date: Tue, 26 Dec 2000 01:22:28 +0000
Subject: Re: sessions and security
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-31809@lists.php.net to get a copy of this message
The session variables all live on the server -- So only somebody who has already compromised your server could access them directly. That would mean you have bigger problems than your web sessions. There's a possibility of somebody sniffing the extremely unpredictable session ID (md5 hash of a randomly-generated value)... But on an SSL connection, that's encrypted, I think. The only *real* risk is users walking off with their browsers still going, and somebody else coming along and using it. Only user-education will make that more secure. ----- Original Message ----- From: Anuradha Ratnaweera <anuradha@gnu.org> Newsgroups: php.general Sent: Thursday, December 21, 2000 10:38 PM Subject: [PHP] sessions and security > > Hi all, > > I have just joined the mailing list, so pardon me if this issue has > already been discussed here. Can anybody direct me to some documentation > on security with session managements. I am wondering if I have a URL based > session system and if a visitor accesses my site (over SSL) through a > proxy, whether someone with access to the proxy logs can access session > variables? > > Thanks in advance. > > > Anuradha > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net >

« previous php.general (#31809) next »