Re: Regenerating session ID automatically when IP address has changed
| From: | Laruence | Date: | Tue, 24 Sep 2013 02:42:25 +0000 |
| Subject: | Re: Regenerating session ID automatically when IP address has changed | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-69304@lists.php.net to get a copy of this message | ||
Hey:
On Tue, Sep 24, 2013 at 10:29 AM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> Hi all,
>
> There isn't any good counter measure session hijack.
> However, we can regenerate session ID if IP address has changed.
> Hijacked users might notice that they have been logged out if session
> ID is regenerated by attackers. Therefore, users have slight chance
> to notice that they were under attack. It's not greatly effective, but
> better than nothing.
I don't think this is language concerning issue.
it could be done in user script..
thanks
>
> Although this can be implemented in user script, it would be better if
> session module supports this behavior. Better security by default
> is good thing. It requires INI, since some apps may assume session
> ID would not change.
> (I do not encourage to use session ID for CSRF protection, but
> there are such implementations, for example.)
>
> A concern is that there are growing number of browsers share
> state. I do not research these browsers behavior yet. I suppose
> session cookie (expire=0) would not be shared.
>
> Anyone has any comments on this?
>
> Regards,
>
> --
> Yasuo Ohgaki
> yohgaki@ohgaki.net
--
Laruence Xinchen Hui
http://www.laruence.com/