note 17335 added to function.session-start

From: Date: Wed, 05 Dec 2001 02:14:51 +0000
Subject: note 17335 added to function.session-start
Groups: php.notes 
Request: Send a blank email to php-notes+get-21620@lists.php.net to get a copy of this message
With regard to all the notes about hashing passwords and session IDs together to improve security, is that really necessary? Unlike HTTP authentication, the only thing the session cookie stores and sends back with each request is the session ID itself. All session data is stored on the server side, so all PHP is doing is a lookup on the specified session ID to find a row in the session storage space that matches the supplied session ID. No other session data is ever transmitted via the browser. With that in mind, it is probably sufficient to use something like: page 1: session_name("test"); session_start(); session_register("logged_in"); $logged_in = true; ... page 2: session_name("test"); session_start(); if (!$HTTP_SESSION_VARS["logged_in"]) { die("You're unauthorized!"); } The key is to never trust the global variable space, and to always reference the explicit arrays that you're expecting data from. No amount of hashing and obscuring session data will save you from an intercepted session ID. The best way to safeguard against hijacked sessions is to minimize their lifetime as much as possible and to only use $HTTP_SESSION_VARS to retrieve session variables. That being said, you should probably hash sensitive session data (e.g., passwords) to prevent others with access to the raw data files (or session database table) from examining them and possibly extracting something useful from them. -- http://www.php.net/manual/en/function.session-start.php http://master.php.net/manage/user-notes.php?action=edit+17335 http://master.php.net/manage/user-notes.php?action=delete+17335 http://master.php.net/manage/user-notes.php?action=reject+17335

« previous php.notes (#21620) next »