Patch to minimize Session Fixation Risks
| From: | inodes | Date: | Wed, 07 Apr 2004 13:56:45 +0000 |
| Subject: | Patch to minimize Session Fixation Risks | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-8959@lists.php.net to get a copy of this message | ||
Hello,
The PHP manual says it is the developer's job to ensure PHP sessions cannot
be stolen or "fixed" (this is called Session Fixation).
To minimise the risk of session fixation, I wrote a patch for PHP-4.3.5 (I
can port it for the other versions too - just ask...), that makes (almost)
sure the current user IS the session creator. It is based on client IP
addresses.
This patch is available at: http://www.trickytools.com/php/sesfixpatch.php
If you think this could be useful, it could be improved and someday be part
of the official distro.
Jerome Delamarche