Re: session flooding
| From: | Tomas V.V.Cox | Date: | Mon, 10 Jun 2002 12:30:26 +0000 |
| Subject: | Re: session flooding | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-6863@lists.php.net to get a copy of this message | ||
Bertrand Mansion wrote:
>
> le 10/06/02 13:55, Tomas V.V.Cox à cox@idecnet.com a écrit :
>
> > "Tomas V.V.Cox" wrote:
> >>
> >> <?php
> >> $sid = md5($_SERVER['REMOTE_ADDR']); //take care also on proxy vars
> >> // if they are set
> >> session_id($sid);
> >> session_start();
> >> ?>
> >>
> >> So you might be forcing the same session file for all the request
> >> instead of 35000 different ones.
> >>
> >> Hope I'm not wrong with my thoughts.
> >>
> >
> > Umm, well, I think I'm wrong :-). In a net with using NAT all the
> > clients appears with the same REMOTE_ADDR, so all they will be sharing
> > the same session vars which is obviously bad.
>
> That's true and also there might be a problem if a user uses a proxy in
> which case the REMOTE_ADDR could be the same for two or more users. Then
> they will have the same session id, won't they ?
Nop, you should check for the $HTTP_X_FORWARDED_FOR var instead of
$REMOTE_ADDR.
BTW, my first example:
<?php
session_start();
if (defined('SID') && SID) {
session_destroy();
}
?>
isn't fullproof as one can easily create a "client" that accepts cookies
but does not remember them accross requests.
Tomas V.V.Cox