note 28632 deleted from ref.session by sniper

From: Date: Tue, 21 Jan 2003 03:10:18 +0000
Subject: note 28632 deleted from ref.session by sniper
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-42466@lists.php.net to get a copy of this message
To avoid session fixation vulnerabilities, it's necessary to replace a given session id before you start a new one. This can be done by: sessionid( md5( uniqid( rand(), TRUE ) . posix_getpid() . rand() ); session_start(); The new session id may not be as random as a session id generated by php (using /dev/urandom is not portable), but it should be enough. [Proposal for future PHP versions]: Declare sessionid() and session_start() depricated and provide three new functions: - session_getid() - session_create() - session_resume([sessionid]) The difference is the semantics: - session_getid() only returns the session id but can not set it - session_create() creates a new session by overriding session ids eventually provied by the browser - session_resume() starts session handling on each page either by using the sessionid provided as parameter or by using the data in a cookie, url, etc ... By splitting session_start() into session_create() and session_resume(), the session fixation vulnerabilities will automagically go away.

« previous php.notes (#42466) next »