note 24427 deleted from function.md5 by jimw

From: Date: Sat, 08 Feb 2003 19:49:53 +0000
Subject: note 24427 deleted from function.md5 by jimw
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-43644@lists.php.net to get a copy of this message
Just a quick security note about some of the comments above. I've seen multiple people recommend computing a hash based on a system timer value and using that as a sessionkey. Your sessionkeys are completely dupable by any competent hacker if you do this. The attacker can do one-way MD5's just like you can - all they have to do is guess the time on your local machine that another client connected and hash that themselves and they're in on a hijacked session. For an active site, especially one that syncs to world time using ntp, it could take only a few hundred attempts to get it right.<p> The proper thing to do is to generate a strong (crypto-quality) pseudo-random number and then md5 hash that. On linux reading /dev/urandom for the input to MD5 would be a good start. Of course, if worried about sessionids and passwords at all, you should probably be doing SSL anyways - and then using MD5-hashed passwords and MD5-hashed random numbers for session keys inside of that.

« previous php.notes (#43644) next »