note 23231 deleted from function.session-start by dams
| From: | dams@php.net | Date: | Sat, 27 Jul 2002 16:49:56 +0000 |
| Subject: | note 23231 deleted from function.session-start by dams | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-33701@lists.php.net to get a copy of this message | ||
I had problems preventing guestbook-spams while inside a session. The problem is, if you directly
access the page via a hacker-programm and are not sending cookies or the session_name and the id,
php creates everytime a new session. This session is initialized as it should be (i have one script
creating all the necessary vars for the session).
It's also not possible to store the IP-address into the database, because of the
proxy-cluster-problem.
This script prevents adding entrys to the forums or guestbook, if the session is not initialized in
the main script (It's nothing special, but maybe you save a hour for other work you got to
do...).
<?php
// This little script tests, if the session id is the same
// as after session_start:
// add this lines into your code, which stores userentrys into database
$savedsession=session_id();
// some other code
include "inc/session.inc.php"; // my session initializer, calls session_start() and
session_register()
// check, if new session is created
if ($savedsession!=sessionid) {
// prevent adding to guestbook, forum etc
}
else {
// here you know, that the user has a valid session,
// but you have to check, if the entry was already entered into the database and don't allow
multiple entrys within a short time )
}
?>
Causch