Solved

Is $_SESSION safe ?

Posted on 2006-10-29
12
412 Views
Last Modified: 2010-05-18
Are the vars stored in $_SESSION safe ? Is there any way a malicious user could change them?
0
Comment
Question by:brightwood
12 Comments
 
LVL 49

Expert Comment

by:Roonaan
ID: 17828390
Session data can be stored in session files that are accessible for other users on your servers. Especially when you are in shared hosting environment, you should use session_save_path() function, to make sure that your sites sessions are stored on your webspace and are inaccessible to other server users.

-r-
0
 
LVL 35

Assisted Solution

by:Raynard7
Raynard7 earned 100 total points
ID: 17828393
Yes - they are safe - they are saved on our server and as such can not be modified, however you must be wary that it is a possibility that someone may replicate the session header and thus access the same session avariables as someone else that is currently using that session - this is a remote possibility, you can do things to stop it such as verifying the IP to the one saved in the session - if you use https however this would also eliminate this problem.
0
 

Author Comment

by:brightwood
ID: 17828426
At this time I'm just using session variables without session_save_path() or without verifying anything. And I'm not using https.

Obviously this isn't safe and I'm looking further to improve my security.

I'm quite new at this, so I'd like some help to use session_save_path() and to check the IP to the one saved in the session.
0
Gigs: Get Your Project Delivered by an Expert

Select from freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely and get projects done right.

 
LVL 4

Accepted Solution

by:
KarlPurkhardt earned 350 total points
ID: 17829175
A good way to validate sessions is to store a unique ID in a cookie and in the session and then validate the user's unique ID (Stored in the cookie) against the session unique ID.  for example, when creating the session

$unique_id = md5(rand(1,999) . time());

$_SESSION['UniqueId'] = $unique_id;
$_SESSION['RemoteAddr'] = $_SERVER['REMOTE_ADDR'];

setcookie('UniqueId', $unique_id, time() + 123456789);

then when you want to verify the user:

if (($_SESSION['UniqueId'] != $_COOKIE['UniqueId']) ||
    ($_SESSION['RemoteAddr'] != $_SERVER['REMOTE_ADDR']))
{
      echo 'Session has been destroyed as a security measure;
     session_destroy();
     setcookie('UniqueId', '', time());
}

Basically what this does is creatre a unique Id when the session is created and stores this in the session and on the users computer using a cookie.  Then, when we want to verify the user we simply compare the unique Id stored in the session against the unique Id stored on the users computer (in their cookie).  If these two don't match we can presume that the user is trying to access someone elses session so we destory the session.  I've also added the RemoteAddr to add an extra level of security, again, this is stored in the session and compared against the users remove address when we want to verify.

Hope that helps.
0
 
LVL 14

Assisted Solution

by:Aamir Saeed
Aamir Saeed earned 50 total points
ID: 17829372
I found this site very helpful regarding session security
http://phpsec.org/projects/guide/4.html
0
 

Author Comment

by:brightwood
ID: 17832891
Thanks for the input KarlPurkhardt. But how I can check if session is already created, so I won't create a new uniqueid and a new cookie everytime my page reloads ?
0
 

Author Comment

by:brightwood
ID: 17832928
Basically when my page loads I want to check if session exists.
- if it doesn't exist: I create the unique id and the cookie.
- if it exists: verify user
0
 

Author Comment

by:brightwood
ID: 17833049
I worked this piece of code:

   if ( isset($_SESSION['UniqueId']) ) {
            if (($_SESSION['UniqueId'] != $_COOKIE['UniqueId']) ||
                  ($_SESSION['RemoteAddr'] != $_SERVER['REMOTE_ADDR']))
            {
                   session_destroy();
                   setcookie('UniqueId', '', time());
                   echo '<script language="JavaScript"> window.location.search = ""; </script>';
            }
   } else {
            $unique_id = md5(rand(1,999) . time());
            
            $_SESSION['UniqueId'] = $unique_id;
            $_SESSION['RemoteAddr'] = $_SERVER['REMOTE_ADDR'];
            
            setcookie('UniqueId', $unique_id, time() + 123456789);
   }

Is is good ?
0
 
LVL 4

Expert Comment

by:KarlPurkhardt
ID: 17833640
Yes that looks fine, although you may want to add another check for the cookie being set, incase the user clears their cookies.  You may also want to change the 123456789 to something a little more practical, atm that is set to keep the cookie for almost 4 years :)

0
 

Author Comment

by:brightwood
ID: 17833799
How I can check if cookie is set please ?
0
 
LVL 4

Expert Comment

by:KarlPurkhardt
ID: 17833902
change:

 if ( isset($_SESSION['UniqueId']) ) {

to  
if  (isset($_SESSION['UniqueId'])  && isset($_COOKIE['UniqueId'])) {
0
 

Author Comment

by:brightwood
ID: 17837054
Got It working I guess, thanks a lot for help.
0

Featured Post

Live: Real-Time Solutions, Start Here

Receive instant 1:1 support from technology experts, using our real-time conversation and whiteboard interface. Your first 5 minutes are always free.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Things That Drive Us Nuts Have you noticed the use of the reCaptcha feature at EE and other web sites?  It wants you to read and retype something that looks like this.Insanity!  It's not EE's fault - that's just the way reCaptcha works.  But it is …
Build an array called $myWeek which will hold the array elements Today, Yesterday and then builds up the rest of the week by the name of the day going back 1 week.   (CODE) (CODE) Then you just need to pass your date to the function. If i…
The viewer will learn how to count occurrences of each item in an array.
The viewer will learn how to create a basic form using some HTML5 and PHP for later processing. Set up your basic HTML file. Open your form tag and set the method and action attributes.: (CODE) Set up your first few inputs one for the name and …

785 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question