Re: session flooding (Re: [PEAR-DEV] We need another Auth)
| From: | Bertrand Mansion | Date: | Mon, 10 Jun 2002 12:16:36 +0000 |
| Subject: | Re: session flooding (Re: [PEAR-DEV] We need another Auth) | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-6860@lists.php.net to get a copy of this message | ||
le 10/06/02 13:55, Tomas V.V.Cox à cox@idecnet.com a écrit :
> "Tomas V.V.Cox" wrote:
>>
>> <?php
>> $sid = md5($_SERVER['REMOTE_ADDR']); //take care also on proxy vars
>> // if they are set
>> session_id($sid);
>> session_start();
>> ?>
>>
>> So you might be forcing the same session file for all the request
>> instead of 35000 different ones.
>>
>> Hope I'm not wrong with my thoughts.
>>
>
> Umm, well, I think I'm wrong :-). In a net with using NAT all the
> clients appears with the same REMOTE_ADDR, so all they will be sharing
> the same session vars which is obviously bad.
That's true and also there might be a problem if a user uses a proxy in
which case the REMOTE_ADDR could be the same for two or more users. Then
they will have the same session id, won't they ?
Bertrand Mansion
Mamasam