note 28632 deleted from ref.session by sniper
| From: | sniper@php.net | Date: | Tue, 21 Jan 2003 03:10:18 +0000 |
| Subject: | note 28632 deleted from ref.session by sniper | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-42466@lists.php.net to get a copy of this message | ||
To avoid session fixation vulnerabilities, it's necessary to replace a given session id before
you start a new one. This can be done by:
sessionid( md5( uniqid( rand(), TRUE ) . posix_getpid() . rand() );
session_start();
The new session id may not be as random as a session id generated by php (using /dev/urandom is not
portable), but it should be enough.
[Proposal for future PHP versions]:
Declare sessionid() and session_start() depricated and provide three new functions:
- session_getid()
- session_create()
- session_resume([sessionid])
The difference is the semantics:
- session_getid() only returns the session id but can not set it
- session_create() creates a new session by overriding session ids eventually provied by the browser
- session_resume() starts session handling on each page either by using the sessionid provided as
parameter or by using the data in a cookie, url, etc ...
By splitting session_start() into session_create() and session_resume(), the session fixation
vulnerabilities will automagically go away.