note 83498 deleted from function.session-start by cmb

From: Date: Mon, 21 Nov 2016 19:08:52 +0000
Subject: note 83498 deleted from function.session-start by cmb
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-207286@lists.php.net to get a copy of this message
Note Submitter: ash at atomic-network dot co dot uk ---- When developing applications or just creating a general website with the use of sessions, many developers do not think about securing session hijacking attacks. For further information I recommend searching google, however I have produced a small function to be called immediately after session_start(). your_page.php: <?php session_start(); include_once 'session_secure.inc.php'; session_secure(); # Your content here. ?> session_secure.inc.php : <?php function session_secure(){ // wrapped for the php entry.... $alph =array('A','a','B','b','C','c','D','d','E', 'e','F','f','G','g','H','h','I','i','J','K','k', 'L','l','M','m','N','n','O','o','P','p','Q','q', 'R','r','S','s','T','t','U','u','V','v','W','w', 'X','x','Y','y','Z','z'); for($i=0;$i<rand(10,20);$i++){ $tmp[] =$alph[rand(0,count($alph))]; $tmp[] =rand(0,9); } return implode("",shuffle($tmp)); } ?> There are quicker ways like md5(time()*rand()), however the function above is completely random, and will render an attackers hijacking task almost impossible.

« previous php.notes (#207286) next »