note 83498 added to function.session-start
| From: | ash at atomic-network dot co dot uk | Date: | Wed, 28 May 2008 16:29:22 +0000 |
| Subject: | note 83498 added to function.session-start | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-139952@lists.php.net to get a copy of this message | ||
When developing applications or just creating a general website with the use of sessions, many
developers do not think about securing session hijacking attacks. For further information I
recommend searching google, however I have produced a small function to be called immediately after
session_start().
your_page.php:
<?php
session_start();
include_once 'session_secure.inc.php';
session_secure();
# Your content here.
?>
session_secure.inc.php :
<?php
function session_secure(){
// wrapped for the php entry....
$alph
=array('A','a','B','b','C','c','D','d','E',
'e','F','f','G','g','H','h','I','i','J','K','k',
'L','l','M','m','N','n','O','o','P','p','Q','q',
'R','r','S','s','T','t','U','u','V','v','W','w',
'X','x','Y','y','Z','z');
for($i=0;$i<rand(10,20);$i++){
$tmp[] =$alph[rand(0,count($alph))];
$tmp[] =rand(0,9);
}
return implode("",shuffle($tmp));
}
?>
There are quicker ways like md5(time()*rand()), however the function above is completely random, and
will render an attackers hijacking task almost impossible.
----
Server IP: 92.48.100.16
Probable Submitter: 81.137.71.201
----
Manual Page -- http://www.php.net/manual/en/function.session-start.php
Edit -- https://master.php.net/note/edit/83498
Del: integrated -- https://master.php.net/note/delete/83498/integrated
Del: useless -- https://master.php.net/note/delete/83498/useless
Del: bad code -- https://master.php.net/note/delete/83498/bad+code
Del: spam -- https://master.php.net/note/delete/83498/spam
Del: non-english -- https://master.php.net/note/delete/83498/non-english
Del: in docs -- https://master.php.net/note/delete/83498/in+docs
Del: other reasons-- https://master.php.net/note/delete/83498
Reject -- https://master.php.net/note/reject/83498
Search -- https://master.php.net/manage/user-notes.php