Re: session flooding

From: Date: Mon, 10 Jun 2002 12:30:26 +0000
Subject: Re: session flooding
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-6863@lists.php.net to get a copy of this message
Bertrand Mansion wrote: > > le 10/06/02 13:55, Tomas V.V.Cox à cox@idecnet.com a écrit : > > > "Tomas V.V.Cox" wrote: > >> > >> <?php > >> $sid = md5($_SERVER['REMOTE_ADDR']); //take care also on proxy vars > >> // if they are set > >> session_id($sid); > >> session_start(); > >> ?> > >> > >> So you might be forcing the same session file for all the request > >> instead of 35000 different ones. > >> > >> Hope I'm not wrong with my thoughts. > >> > > > > Umm, well, I think I'm wrong :-). In a net with using NAT all the > > clients appears with the same REMOTE_ADDR, so all they will be sharing > > the same session vars which is obviously bad. > > That's true and also there might be a problem if a user uses a proxy in > which case the REMOTE_ADDR could be the same for two or more users. Then > they will have the same session id, won't they ? Nop, you should check for the $HTTP_X_FORWARDED_FOR var instead of $REMOTE_ADDR. BTW, my first example: <?php session_start(); if (defined('SID') && SID) { session_destroy(); } ?> isn't fullproof as one can easily create a "client" that accepts cookies but does not remember them accross requests. Tomas V.V.Cox

« previous php.pear.dev (#6863) next »