Re: sessions and security
| From: | Richard Lynch | Date: | Tue, 26 Dec 2000 01:22:28 +0000 |
| Subject: | Re: sessions and security | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-31809@lists.php.net to get a copy of this message | ||
The session variables all live on the server -- So only somebody who has
already compromised your server could access them directly. That would mean
you have bigger problems than your web sessions.
There's a possibility of somebody sniffing the extremely unpredictable
session ID (md5 hash of a randomly-generated value)... But on an SSL
connection, that's encrypted, I think.
The only *real* risk is users walking off with their browsers still going,
and somebody else coming along and using it. Only user-education will make
that more secure.
----- Original Message -----
From: Anuradha Ratnaweera <anuradha@gnu.org>
Newsgroups: php.general
Sent: Thursday, December 21, 2000 10:38 PM
Subject: [PHP] sessions and security
>
> Hi all,
>
> I have just joined the mailing list, so pardon me if this issue has
> already been discussed here. Can anybody direct me to some documentation
> on security with session managements. I am wondering if I have a URL based
> session system and if a visitor accesses my site (over SSL) through a
> proxy, whether someone with access to the proxy logs can access session
> variables?
>
> Thanks in advance.
>
>
> Anuradha
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>