note 24427 deleted from function.md5 by jimw
| From: | jimw@php.net | Date: | Sat, 08 Feb 2003 19:49:53 +0000 |
| Subject: | note 24427 deleted from function.md5 by jimw | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-43644@lists.php.net to get a copy of this message | ||
Just a quick security note about some of the comments above. I've seen multiple people
recommend computing a hash based on a system timer value and using that as a sessionkey. Your
sessionkeys are completely dupable by any competent hacker if you do this. The attacker can do
one-way MD5's just like you can - all they have to do is guess the time on your local machine
that another client connected and hash that themselves and they're in on a hijacked session.
For an active site, especially one that syncs to world time using ntp, it could take only a few
hundred attempts to get it right.<p> The proper thing to do is to generate a strong
(crypto-quality) pseudo-random number and then md5 hash that. On linux reading /dev/urandom for the
input to MD5 would be a good start.
Of course, if worried about sessionids and passwords at all, you should probably be doing SSL
anyways - and then using MD5-hashed passwords and MD5-hashed random numbers for session keys inside
of that.