Re: Regenerating session ID automatically when IP address has changed

From: Date: Tue, 24 Sep 2013 02:42:25 +0000
Subject: Re: Regenerating session ID automatically when IP address has changed
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-69304@lists.php.net to get a copy of this message
Hey: On Tue, Sep 24, 2013 at 10:29 AM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > Hi all, > > There isn't any good counter measure session hijack. > However, we can regenerate session ID if IP address has changed. > Hijacked users might notice that they have been logged out if session > ID is regenerated by attackers. Therefore, users have slight chance > to notice that they were under attack. It's not greatly effective, but > better than nothing. I don't think this is language concerning issue. it could be done in user script.. thanks > > Although this can be implemented in user script, it would be better if > session module supports this behavior. Better security by default > is good thing. It requires INI, since some apps may assume session > ID would not change. > (I do not encourage to use session ID for CSRF protection, but > there are such implementations, for example.) > > A concern is that there are growing number of browsers share > state. I do not research these browsers behavior yet. I suppose > session cookie (expire=0) would not be shared. > > Anyone has any comments on this? > > Regards, > > -- > Yasuo Ohgaki > yohgaki@ohgaki.net -- Laruence Xinchen Hui http://www.laruence.com/

« previous php.internals (#69304) next »