Solved

Is $_SESSION safe ?

Posted on 2006-10-29
12
410 Views
Last Modified: 2010-05-18
Are the vars stored in $_SESSION safe ? Is there any way a malicious user could change them?
0
Comment
Question by:brightwood
12 Comments
 
LVL 49

Expert Comment

by:Roonaan
ID: 17828390
Session data can be stored in session files that are accessible for other users on your servers. Especially when you are in shared hosting environment, you should use session_save_path() function, to make sure that your sites sessions are stored on your webspace and are inaccessible to other server users.

-r-
0
 
LVL 35

Assisted Solution

by:Raynard7
Raynard7 earned 100 total points
ID: 17828393
Yes - they are safe - they are saved on our server and as such can not be modified, however you must be wary that it is a possibility that someone may replicate the session header and thus access the same session avariables as someone else that is currently using that session - this is a remote possibility, you can do things to stop it such as verifying the IP to the one saved in the session - if you use https however this would also eliminate this problem.
0
 

Author Comment

by:brightwood
ID: 17828426
At this time I'm just using session variables without session_save_path() or without verifying anything. And I'm not using https.

Obviously this isn't safe and I'm looking further to improve my security.

I'm quite new at this, so I'd like some help to use session_save_path() and to check the IP to the one saved in the session.
0
 
LVL 4

Accepted Solution

by:
KarlPurkhardt earned 350 total points
ID: 17829175
A good way to validate sessions is to store a unique ID in a cookie and in the session and then validate the user's unique ID (Stored in the cookie) against the session unique ID.  for example, when creating the session

$unique_id = md5(rand(1,999) . time());

$_SESSION['UniqueId'] = $unique_id;
$_SESSION['RemoteAddr'] = $_SERVER['REMOTE_ADDR'];

setcookie('UniqueId', $unique_id, time() + 123456789);

then when you want to verify the user:

if (($_SESSION['UniqueId'] != $_COOKIE['UniqueId']) ||
    ($_SESSION['RemoteAddr'] != $_SERVER['REMOTE_ADDR']))
{
      echo 'Session has been destroyed as a security measure;
     session_destroy();
     setcookie('UniqueId', '', time());
}

Basically what this does is creatre a unique Id when the session is created and stores this in the session and on the users computer using a cookie.  Then, when we want to verify the user we simply compare the unique Id stored in the session against the unique Id stored on the users computer (in their cookie).  If these two don't match we can presume that the user is trying to access someone elses session so we destory the session.  I've also added the RemoteAddr to add an extra level of security, again, this is stored in the session and compared against the users remove address when we want to verify.

Hope that helps.
0
 
LVL 14

Assisted Solution

by:Aamir Saeed
Aamir Saeed earned 50 total points
ID: 17829372
I found this site very helpful regarding session security
http://phpsec.org/projects/guide/4.html
0
 

Author Comment

by:brightwood
ID: 17832891
Thanks for the input KarlPurkhardt. But how I can check if session is already created, so I won't create a new uniqueid and a new cookie everytime my page reloads ?
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 

Author Comment

by:brightwood
ID: 17832928
Basically when my page loads I want to check if session exists.
- if it doesn't exist: I create the unique id and the cookie.
- if it exists: verify user
0
 

Author Comment

by:brightwood
ID: 17833049
I worked this piece of code:

   if ( isset($_SESSION['UniqueId']) ) {
            if (($_SESSION['UniqueId'] != $_COOKIE['UniqueId']) ||
                  ($_SESSION['RemoteAddr'] != $_SERVER['REMOTE_ADDR']))
            {
                   session_destroy();
                   setcookie('UniqueId', '', time());
                   echo '<script language="JavaScript"> window.location.search = ""; </script>';
            }
   } else {
            $unique_id = md5(rand(1,999) . time());
            
            $_SESSION['UniqueId'] = $unique_id;
            $_SESSION['RemoteAddr'] = $_SERVER['REMOTE_ADDR'];
            
            setcookie('UniqueId', $unique_id, time() + 123456789);
   }

Is is good ?
0
 
LVL 4

Expert Comment

by:KarlPurkhardt
ID: 17833640
Yes that looks fine, although you may want to add another check for the cookie being set, incase the user clears their cookies.  You may also want to change the 123456789 to something a little more practical, atm that is set to keep the cookie for almost 4 years :)

0
 

Author Comment

by:brightwood
ID: 17833799
How I can check if cookie is set please ?
0
 
LVL 4

Expert Comment

by:KarlPurkhardt
ID: 17833902
change:

 if ( isset($_SESSION['UniqueId']) ) {

to  
if  (isset($_SESSION['UniqueId'])  && isset($_COOKIE['UniqueId'])) {
0
 

Author Comment

by:brightwood
ID: 17837054
Got It working I guess, thanks a lot for help.
0

Featured Post

Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

Join & Write a Comment

Deprecated and Headed for the Dustbin By now, you have probably heard that some PHP features, while convenient, can also cause PHP security problems.  This article discusses one of those, called register_globals.  It is a thing you do not want.  …
Password hashing is better than message digests or encryption, and you should be using it instead of message digests or encryption.  Find out why and how in this article, which supplements the original article on PHP Client Registration, Login, Logo…
Learn how to match and substitute tagged data using PHP regular expressions. Demonstrated on Windows 7, but also applies to other operating systems. Demonstrated technique applies to PHP (all versions) and Firefox, but very similar techniques will w…
The viewer will learn how to look for a specific file type in a local or remote server directory using PHP.

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now