session flooding (Re: [PEAR-DEV] We need another Auth)
| From: | Tomas V.V.Cox | Date: | Mon, 10 Jun 2002 11:43:21 +0000 |
| Subject: | session flooding (Re: [PEAR-DEV] We need another Auth) | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-6854@lists.php.net to get a copy of this message | ||
Bertrand Mansion wrote:
>
> Hi,
>
> I have had so much difficulties to adapt Auth to my own need. The class is
> not flexible enough and might be good for a very basic authentication system
> but not for a complete web application.
>
> I think we need a better authentication system.
>
> This morning, I indexed 35 000 pages using htdig on a website I run
> (http://cocoa.mamasam.com). The indexing crashed because of the way Auth
> handles sessions. I don't understand why there is a session_start() in the
> class start() method. This will start a new session everytime htdig accesses
> a new page. I ended up with 35 000 session files in the session directory !
Do that:
<?php
session_start();
/*
From PHP Manual:
"Alternatively, you can use the constant SID which is defined, if the
client did not send the appropriate cookie"
*/
if (defined('SID') && SID) {
session_destroy();
}
?>
This will prevent your session flooding. Well not entirely because you
will end doing 35000 "create/destroy"'s file. Perhaps for being more
clever about session flooding attemps you could do something like:
<?php
$sid = md5($_SERVER['REMOTE_ADDR']); //take care also on proxy vars
// if they are set
session_id($sid);
session_start();
?>
So you might be forcing the same session file for all the request
instead of 35000 different ones.
Hope I'm not wrong with my thoughts.
Tomas V.V.Cox