note 63789 deleted from function.serialize by aharvey
| From: | aharvey@php.net | Date: | Tue, 06 Nov 2012 02:10:50 +0000 |
| Subject: | note 63789 deleted from function.serialize by aharvey | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-191772@lists.php.net to get a copy of this message | ||
Note Submitter: erudd at netfor dot com
----
To unserialize a PHP session file, unserlize can not be used directly.
The data must be split, as the php session file also contains the names of the variables which
serialize/unserialize do not do. Here is a simple preg_split that will acomplish the split.. (regex
not thuroughly tested, but should work for most all circumstances)
<?php
$session = file_get_contents($session_file);
$data = preg_split('/([A-Za-z_][A-Za-z0-9_]*)\|/',$session,-1,
PREG_SPLIT_DELIM_CAPTURE|PREG_SPLIT_NO_EMPTY);
?>
$data[0] will contain the variable name, and $data[1] will contain the serialized data. so in
effect
<?php
$$data[0] = unserialize($data[1]);
?>
will restore that one variable.
just go through the $data array evens being the variable name, odd being the data. You can use this
to create a simple command line session viewer:)