session flooding (Re: [PEAR-DEV] We need another Auth)

From: Date: Mon, 10 Jun 2002 11:43:21 +0000
Subject: session flooding (Re: [PEAR-DEV] We need another Auth)
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-6854@lists.php.net to get a copy of this message
Bertrand Mansion wrote: > > Hi, > > I have had so much difficulties to adapt Auth to my own need. The class is > not flexible enough and might be good for a very basic authentication system > but not for a complete web application. > > I think we need a better authentication system. > > This morning, I indexed 35 000 pages using htdig on a website I run > (http://cocoa.mamasam.com). The indexing crashed because of the way Auth > handles sessions. I don't understand why there is a session_start() in the > class start() method. This will start a new session everytime htdig accesses > a new page. I ended up with 35 000 session files in the session directory ! Do that: <?php session_start(); /* From PHP Manual: "Alternatively, you can use the constant SID which is defined, if the client did not send the appropriate cookie" */ if (defined('SID') && SID) { session_destroy(); } ?> This will prevent your session flooding. Well not entirely because you will end doing 35000 "create/destroy"'s file. Perhaps for being more clever about session flooding attemps you could do something like: <?php $sid = md5($_SERVER['REMOTE_ADDR']); //take care also on proxy vars // if they are set session_id($sid); session_start(); ?> So you might be forcing the same session file for all the request instead of 35000 different ones. Hope I'm not wrong with my thoughts. Tomas V.V.Cox

« previous php.pear.dev (#6854) next »