note 83498 deleted from function.session-start by cmb
| From: | cmb@php.net | Date: | Mon, 21 Nov 2016 19:08:52 +0000 |
| Subject: | note 83498 deleted from function.session-start by cmb | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-207286@lists.php.net to get a copy of this message | ||
Note Submitter: ash at atomic-network dot co dot uk
----
When developing applications or just creating a general website with the use of sessions, many
developers do not think about securing session hijacking attacks. For further information I
recommend searching google, however I have produced a small function to be called immediately after
session_start().
your_page.php:
<?php
session_start();
include_once 'session_secure.inc.php';
session_secure();
# Your content here.
?>
session_secure.inc.php :
<?php
function session_secure(){
// wrapped for the php entry....
$alph
=array('A','a','B','b','C','c','D','d','E',
'e','F','f','G','g','H','h','I','i','J','K','k',
'L','l','M','m','N','n','O','o','P','p','Q','q',
'R','r','S','s','T','t','U','u','V','v','W','w',
'X','x','Y','y','Z','z');
for($i=0;$i<rand(10,20);$i++){
$tmp[] =$alph[rand(0,count($alph))];
$tmp[] =rand(0,9);
}
return implode("",shuffle($tmp));
}
?>
There are quicker ways like md5(time()*rand()), however the function above is completely random, and
will render an attackers hijacking task almost impossible.