Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

PHP Forum


You are currently viewing our PHP Forum as a guest. Please register to participate.
Login



Freelance Jobs

Reply
How secure is storing data in a session?
Old 12-24-2009, 10:49 AM How secure is storing data in a session?
lynxus's Avatar
Awesomeo-Maximo

Posts: 1,618
Location: UK
Trades: 1
( Fully aware of the amount of posts I seem to do, I Prefer multiple peoples opinions rather than some random website )

Hi Guys,

After recently looking at another post, Im wondering just how secure keeping data in a session is?

As far as im aware, Its all server side and cant be hijacked? or injected?


if i put data into a session and then rely on said data on other pages for sql querys etc.
Can i trust it hasn't been tampered with remotely ( assuming the server itself hasn't been compromised )


Your thoughts?

-G
__________________

Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE



Last edited by lynxus; 12-24-2009 at 10:52 AM..
lynxus is offline
Reply With Quote
View Public Profile Visit lynxus's homepage!
 
 
Register now for full access!
Old 12-24-2009, 11:03 AM Re: How secure is storing data in a session?
chrishirst's Avatar
Missing! presumed drunk.

Posts: 42,384
Name: Chris Hirst
Location: Blackpool. UK
Trades: 0
A session only exists between your browser and the server. Even other browsers on your machine cannot read the same session data.
__________________
Chris. ->>
Please login or register to view this content. Registration is FREE
<<-

A foolish consistency is the hobgoblin of little minds
Thought for today:- Is SEO the only industry where all the cowboys are Indians?
chrishirst is online now
Reply With Quote
View Public Profile Visit chrishirst's homepage!
 
Old 12-24-2009, 11:08 AM Re: How secure is storing data in a session?
lynxus's Avatar
Awesomeo-Maximo

Posts: 1,618
Location: UK
Trades: 1
But can someone inject a session? or modify it ? or even view it?
__________________

Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE


lynxus is offline
Reply With Quote
View Public Profile Visit lynxus's homepage!
 
Old 12-24-2009, 11:17 AM Re: How secure is storing data in a session?
chrishirst's Avatar
Missing! presumed drunk.

Posts: 42,384
Name: Chris Hirst
Location: Blackpool. UK
Trades: 0
Quote:
Even other browsers on your machine cannot read the same session data.
?? .....
__________________
Chris. ->>
Please login or register to view this content. Registration is FREE
<<-

A foolish consistency is the hobgoblin of little minds
Thought for today:- Is SEO the only industry where all the cowboys are Indians?
chrishirst is online now
Reply With Quote
View Public Profile Visit chrishirst's homepage!
 
Old 12-24-2009, 11:18 AM Re: How secure is storing data in a session?
lynxus's Avatar
Awesomeo-Maximo

Posts: 1,618
Location: UK
Trades: 1
OK, probably a stupid question then ty
__________________

Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE


lynxus is offline
Reply With Quote
View Public Profile Visit lynxus's homepage!
 
Old 12-29-2009, 09:43 AM Re: How secure is storing data in a session?
Novice Talker

Posts: 11
Name: syafiq
Trades: 0
i think session store has secure. because it store temporary file and unique name on server.
__________________
>>
Please login or register to view this content. Registration is FREE
||
Please login or register to view this content. Registration is FREE
<<
hotsmusic is offline
Reply With Quote
View Public Profile
 
Old 12-29-2009, 03:49 PM Re: How secure is storing data in a session?
tripy's Avatar
Do not try this at home!

Posts: 3,621
Name: Thierry
Location: I'm the uber Spaminator !
Trades: 0
Quote:
But can someone inject a session? or modify it ? or even view it?
Yes, if you give them the possibility.
It's depending on how you code.
Imagint that you have a page, named session.php, that is like this:
PHP Code:
<?php
foreach($_GET as $key=>$val){
    
$_SESSION[$key]=$val;
}
?>
Then yes, they can inject whatever they want into the session.

But there is nothing that allows a user to alter his session without you knowing it or doing something that explicitly permits him to do so.
__________________
Only a biker knows why a dog sticks his head out the window.
tripy is offline
Reply With Quote
View Public Profile Visit tripy's homepage!
 
Old 12-29-2009, 04:00 PM Re: How secure is storing data in a session?
lynxus's Avatar
Awesomeo-Maximo

Posts: 1,618
Location: UK
Trades: 1
Ok thats good.

i dont put data into sessions based on user input. Its always up to the script what to put in and cannot be infulenced.

I just wanted to make sure there was no way for them to send odd stuff and modify sessions.

While i do understand how the work , where it stores them and how to retrieve them, I have worked in the IT industry for many years now at a very high level and have come across MANY seemingly impossible to do things done.

So just wanted to be sure before i get myself in a situation i could of steered away from.

Thanks
G
__________________

Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE

Please login or register to view this content. Registration is FREE


lynxus is offline
Reply With Quote
View Public Profile Visit lynxus's homepage!
 
Reply     « Reply to How secure is storing data in a session?
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.46733 seconds with 12 queries