You are here: Re: session management- your opinion « PHP Programming Language « IT news, forums, messages
Re: session management- your opinion

Posted by julianmlp on 05/28/06 01:38

Jerry Stuckle wrote:
> julianmlp@gmail.com wrote:
>
> > What I was wondering is: Is there any (simple/easy) way to hijack a
> > cookie remotely? (to be afraid of)
> >
>
> Not unless you can intercept the packets somewhere between the server and the
> client, or have access to the server file system (assuming you are using the
> default session handler in PHP).

I'm not using the default session handler.

I pass the session ID as

url_to_my_file.php?session=VALUE,

where VALUE is created from:

VALUE = md5(uniqid(rand(), true));

CookieValue = sha1(VALUE + HiddenString);


When I receive a client request, I lookup for the session AND the
cookie's value to see whether the client is logged or not.
It seems to me pretty safe, but I'm not an expert at all...

 

Navigation:

[Reply to this message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация