Re: Re: cookies and sessions security
| From: | Kristofer Widholm | Date: | Tue, 16 Jan 2001 07:32:35 +0000 |
| Subject: | Re: Re: cookies and sessions security | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-34774@lists.php.net to get a copy of this message | ||
At 14.54 -0500 01-01-15, Tim Zickus poked the keyboard as follows:
Wow, I never thought of using the remote IP! Thanks for the tip. IObviously, this means that the system could be vulnerable to being compromised by someone working through a large ISP such as AOL, but I think it's unlikely that people with the expertise to sniff cookies and such would be using AOL. And anyway, the system would still be more secure than if I weren't using IP verification at all. Does anyone one know of a class or function that's been already built to do this? Kristofer -- ______________________________________ Kristofer Widholm Web Pharmacy webpharmacy@brokenhill.net 191 Grand Street, Brooklyn NY 11211 718.599.4893 ______________________________________am going to use it today for an authentication system I'm building.Please note that remote IP is NOT reliable. For clients behind the proxies & gateways of large ISP's (AOL is the prime example) you can see the remote address bounce around from number to number, even within the same session, depending on which path the data takes. Ach, oy vey! Then, having looked at AOL's info, it seems to me that perhaps one could build a function or class that could evaluate against a known list of alternate proxies. So, if the request came from 152.163.197, it would recognize that as an AOL proxy and just code the current proxy as "AOL" or something. Each subsequent request (from 152.163.* etc.) would go through the same filter.