RE: [PEAR] New features in Auth
| From: | Marius Mathiesen | Date: | Wed, 25 Feb 2004 08:46:40 +0000 |
| Subject: | RE: [PEAR] New features in Auth | ||
| References: | 1 | Groups: | php.pear.general |
| Request: | Send a blank email to pear-general+get-10918@lists.php.net to get a copy of this message | ||
> =========================Avoid session hijacking
>>Hmm I never knew that was possible.
Well, it is :-) Really, it's all about a man-in-the-middle getting hold of
your session identifier and use that to access the server. CERT has an
advisory on it at http://www.cert.org/advisories/CA-2000-02.html
> Anyway,
> currently the system is set up to 1st check wether someone is logged in,
> and only if that is not true it will try to log you in with the specified
> credentials. And checking wether you are logged in means you need to start
> the session.
Well, yes. Or you could check if there _is_ indeed a session established
first. If there isn't a session, we implicitly know that the user isn't
logged in, right?
A quite simple way to check the existence of a session would be to check
if the user has presented a cookie with the same name as the session
identifier.
> I think it would need serious changing of all modules (tear apart
> credential checking and actual logging in, so credential checking can be
> done before session_start and logging in after), so I don't know how big
> this issue really is.
Neither do I...
> As for system generated session_ids. I don't know how you want to
> distinguish between both. One way would be to actually store nothing in
> the session_cookie expect for the id, and save all additional information
> in a database table. That way one can spoof a session_id, but since there
> is no corresponding db-record it won't help.
Well, one way could be to use some sort of checksum technique to validate
the session id. For instance:
$sessid = base64_encode(md5("MY_SECRET_PASSWORD$$".$_SERVER[REMOTE_ADDR]));
where MY_SECRET_PASSWORD could be changed to whatever you want. This way,
you could use the same algorithm to validate the user's IP...
>
> =========================Register user's IP in session
> =========================
> If I'm right this feature allready exists. The
> latest version I see in CVS has advanced scurity, which can be enabled
> with setAdvancedSecurity(true)
I think you're right... Shame on me for not checking the CVS version :-)
> Maybe this gives some idea's to any of the 3 maintainers of the Auth
> package.
Thanks for your feedback, Herman!
Regards, Marius
> Herman
--
The trouble with being in the rat race is that even if you win, you're
still a rat. - Lily Tomlin
Please note that all email to this address will be scanned for spam.