note 24427 modified in function.md5 by nicos
| From: | nicos@php.net | Date: | Tue, 14 Jan 2003 13:26:48 +0000 |
| Subject: | note 24427 modified in function.md5 by nicos | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-42122@lists.php.net to get a copy of this message | ||
Just a quick security note about some of the comments above. I've seen multiple people
recommend computing a hash based on a system timer value and using that as a sessionkey. Your
sessionkeys are completely dupable by any competent hacker if you do this. The attacker can do
one-way MD5's just like you can - all they have to do is guess the time on your local machine
that another client connected and hash that themselves and they're in on a hijacked session.
For an active site, especially one that syncs to world time using ntp, it could take only a few
hundred attempts to get it right.<p> The proper thing to do is to generate a strong
(crypto-quality) pseudo-random number and then md5 hash that. On linux reading /dev/urandom for the
input to MD5 would be a good start.
Of course, if worried about sessionids and passwords at all, you should probably be doing SSL
anyways - and then using MD5-hashed passwords and MD5-hashed random numbers for session keys inside
of that.
--was--
<p>
Just a quick security note about some of the comments above. I've seen multiple people
recommend computing a hash based on a system timer value and using that as a sessionkey. Your
sessionkeys are completely dupable by any competent hacker if you do this. The attacker can do
one-way MD5's just like you can - all they have to do is guess the time on your local machine
that another client connected and hash that themselves and they're in on a hijacked session.
For an active site, especially one that syncs to world time using ntp, it could take only a few
hundred attempts to get it right.<p> The proper thing to do is to generate a strong
(crypto-quality) pseudo-random number and then md5 hash that. On linux reading /dev/urandom for the
input to MD5 would be a good start.</p>
<p>
Of course, if worried about sessionids and passwords at all, you should probably be doing SSL
anyways - and then using MD5-hashed passwords and MD5-hashed random numbers for session keys inside
of that.</p>
http://www.php.net/manual/en/function.md5.php