RE: [PHP] Stopping stolen / spoofed / linked sessions
| From: | dahamsta) | Date: | Thu, 28 Jun 2001 16:16:36 +0000 |
| Subject: | RE: [PHP] Stopping stolen / spoofed / linked sessions | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-55507@lists.php.net to get a copy of this message | ||
David Price <dprice@info-logix.com> said:
> They way I got around this was to create a session key using a MD5 hash of
> the session id and the user's IP address.
>
<SNIP>
>
> I know that the IP address can be spoofed, but I'm not sending the session
> id in the url, so no one knows what it is and without the session id the
> session key can not be spoofed.
>
IP spoofing is only a side issue - some users IP address changes from request
to request. WebTV is an example, and users behind proxies is another.
I guess I'm looking for the perfect solution here, which just doesn't appear
to be possible with HTTP. Maybe a better question is: "What is the ideal
model for a PHP4 sessions authentication scheme?"
Thanks anyway,
adam