RE: [PEAR] New features in Auth

From: Date: Wed, 25 Feb 2004 08:46:40 +0000
Subject: RE: [PEAR] New features in Auth
References: 1  Groups: php.pear.general 
Request: Send a blank email to pear-general+get-10918@lists.php.net to get a copy of this message
> =========================Avoid session hijacking >>Hmm I never knew that was possible. Well, it is :-) Really, it's all about a man-in-the-middle getting hold of your session identifier and use that to access the server. CERT has an advisory on it at http://www.cert.org/advisories/CA-2000-02.html > Anyway, > currently the system is set up to 1st check wether someone is logged in, > and only if that is not true it will try to log you in with the specified > credentials. And checking wether you are logged in means you need to start > the session. Well, yes. Or you could check if there _is_ indeed a session established first. If there isn't a session, we implicitly know that the user isn't logged in, right? A quite simple way to check the existence of a session would be to check if the user has presented a cookie with the same name as the session identifier. > I think it would need serious changing of all modules (tear apart > credential checking and actual logging in, so credential checking can be > done before session_start and logging in after), so I don't know how big > this issue really is. Neither do I... > As for system generated session_ids. I don't know how you want to > distinguish between both. One way would be to actually store nothing in > the session_cookie expect for the id, and save all additional information > in a database table. That way one can spoof a session_id, but since there > is no corresponding db-record it won't help. Well, one way could be to use some sort of checksum technique to validate the session id. For instance: $sessid = base64_encode(md5("MY_SECRET_PASSWORD$$".$_SERVER[REMOTE_ADDR])); where MY_SECRET_PASSWORD could be changed to whatever you want. This way, you could use the same algorithm to validate the user's IP... > > =========================Register user's IP in session > ========================= > If I'm right this feature allready exists. The > latest version I see in CVS has advanced scurity, which can be enabled > with setAdvancedSecurity(true) I think you're right... Shame on me for not checking the CVS version :-) > Maybe this gives some idea's to any of the 3 maintainers of the Auth > package. Thanks for your feedback, Herman! Regards, Marius > Herman -- The trouble with being in the rat race is that even if you win, you're still a rat. - Lily Tomlin Please note that all email to this address will be scanned for spam.

« previous php.pear.general (#10918) next »