note 17335 added to function.session-start
| From: | pudnucker at hotmail dot com | Date: | Wed, 05 Dec 2001 02:14:51 +0000 |
| Subject: | note 17335 added to function.session-start | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-21620@lists.php.net to get a copy of this message | ||
With regard to all the notes about hashing passwords and session IDs together to improve security,
is that really necessary? Unlike HTTP authentication, the only thing the session cookie stores and
sends back with each request is the session ID itself. All session data is stored on the server
side, so all PHP is doing is a lookup on the specified session ID to find a row in the session
storage space that matches the supplied session ID. No other session data is ever transmitted via
the browser. With that in mind, it is probably sufficient to use something like:
page 1:
session_name("test");
session_start();
session_register("logged_in");
$logged_in = true;
...
page 2:
session_name("test");
session_start();
if (!$HTTP_SESSION_VARS["logged_in"]) {
die("You're unauthorized!");
}
The key is to never trust the global variable space, and to always reference the explicit arrays
that you're expecting data from.
No amount of hashing and obscuring session data will save you from an intercepted session ID. The
best way to safeguard against hijacked sessions is to minimize their lifetime as much as possible
and to only use $HTTP_SESSION_VARS to retrieve session variables. That being said, you should
probably hash sensitive session data (e.g., passwords) to prevent others with access to the raw data
files (or session database table) from examining them and possibly extracting something useful from
them.
--
http://www.php.net/manual/en/function.session-start.php
http://master.php.net/manage/user-notes.php?action=edit+17335
http://master.php.net/manage/user-notes.php?action=delete+17335
http://master.php.net/manage/user-notes.php?action=reject+17335