note 28632 added to ref.session
| From: | norbert at linuxnetworks dot de | Date: | Sat, 18 Jan 2003 19:01:09 +0000 |
| Subject: | note 28632 added to ref.session | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-42364@lists.php.net to get a copy of this message | ||
To avoid session fixation vulnerabilities, it's necessary to replace a given session id before
you start a new one. This can be done by:
sessionid( md5( uniqid( rand(), TRUE ) . posix_getpid() . rand() );
session_start();
The new session id may not be as random as a session id generated by php (using /dev/urandom is not
portable), but it should be enough.
[Proposal for future PHP versions]:
Declare sessionid() and session_start() depricated and provide three new functions:
- session_getid()
- session_create()
- session_resume([sessionid])
The difference is the semantics:
- session_getid() only returns the session id but can not set it
- session_create() creates a new session by overriding session ids eventually provied by the browser
- session_resume() starts session handling on each page either by using the sessionid provided as
parameter or by using the data in a cookie, url, etc ...
By splitting session_start() into session_create() and session_resume(), the session fixation
vulnerabilities will automagically go away.
--
http://www.php.net/manual/en/ref.session.php
http://master.php.net/manage/user-notes.php?action=edit+28632
http://master.php.net/manage/user-notes.php?action=delete+28632
http://master.php.net/manage/user-notes.php?action=reject+28632