Patch to minimize Session Fixation Risks

From: Date: Wed, 07 Apr 2004 13:56:45 +0000
Subject: Patch to minimize Session Fixation Risks
Groups: php.internals 
Request: Send a blank email to internals+get-8959@lists.php.net to get a copy of this message
Hello, The PHP manual says it is the developer's job to ensure PHP sessions cannot be stolen or "fixed" (this is called Session Fixation). To minimise the risk of session fixation, I wrote a patch for PHP-4.3.5 (I can port it for the other versions too - just ask...), that makes (almost) sure the current user IS the session creator. It is based on client IP addresses. This patch is available at: http://www.trickytools.com/php/sesfixpatch.php If you think this could be useful, it could be improved and someday be part of the official distro. Jerome Delamarche

« previous php.internals (#8959) next »