note 28632 added to ref.session

From: Date: Sat, 18 Jan 2003 19:01:09 +0000
Subject: note 28632 added to ref.session
Groups: php.notes 
Request: Send a blank email to php-notes+get-42364@lists.php.net to get a copy of this message
To avoid session fixation vulnerabilities, it's necessary to replace a given session id before you start a new one. This can be done by: sessionid( md5( uniqid( rand(), TRUE ) . posix_getpid() . rand() ); session_start(); The new session id may not be as random as a session id generated by php (using /dev/urandom is not portable), but it should be enough. [Proposal for future PHP versions]: Declare sessionid() and session_start() depricated and provide three new functions: - session_getid() - session_create() - session_resume([sessionid]) The difference is the semantics: - session_getid() only returns the session id but can not set it - session_create() creates a new session by overriding session ids eventually provied by the browser - session_resume() starts session handling on each page either by using the sessionid provided as parameter or by using the data in a cookie, url, etc ... By splitting session_start() into session_create() and session_resume(), the session fixation vulnerabilities will automagically go away. -- http://www.php.net/manual/en/ref.session.php http://master.php.net/manage/user-notes.php?action=edit+28632 http://master.php.net/manage/user-notes.php?action=delete+28632 http://master.php.net/manage/user-notes.php?action=reject+28632

« previous php.notes (#42364) next »