Re: Patch to minimize session fixation (continued)
| From: | Derick Rethans | Date: | Wed, 07 Apr 2004 20:52:10 +0000 |
| Subject: | Re: Patch to minimize session fixation (continued) | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-8972@lists.php.net to get a copy of this message | ||
On Wed, 7 Apr 2004, Chris Shiflett wrote:
> --- Christian Schneider <cschneid@cschneid.com> wrote:
> > I decided to say "If X knows the session ID of User A then he _is_ A".
>
> This isn't a good approach, but you can bring this up on php-general to
> discuss why. I'm sure plenty of people will be happy to discuss it.
>
> > (Side note: I use my own random/MD5-based session IDs which should be
> > hard to guess).
PHP's generated from remote ID, process id, time and some randomness;
and then MD5'ed. That's 'better' then your random/MD5 based approach as
it's even less likely to result in collisions.
regards,
Derick