Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #3682

Re: session cookie: client side

From Jerry Stuckle <jstucklex@attglobal.net>
Newsgroups comp.lang.php
Subject Re: session cookie: client side
Date 2011-11-04 07:55 -0400
Organization A noiseless patient Spider
Message-ID <j90jsq$550$1@dont-email.me> (permalink)
References <j8tlr0$idi$1@news.albasani.net> <4147316.976.1320323017283.JavaMail.geo-discussion-forums@yqnv12> <j8vvsn$ub6$1@news.albasani.net>

Show all headers | View raw


On 11/4/2011 2:14 AM, sl@exabyte wrote:
>> I don't know I understood your question totally but...
>>
>> If the user can read the session cookie then any others can read the
>> session cookie. The browser can't recognize who sits in front of the
>> monitor.
>>
>> Another way: If user can read session cookie + it's not an SSL
>> channel ->  any others can sniff it (local machine or another machine
>> on the route/wifi)
>>
>> Mechanism: on server side the system generates a Session ID (SID).
>> The SID identifies the session datas ($_SESSION in PHP). The Server
>> store session data in a file or database. on client side the client
>> knows only the SID but the client doesn't know session data, only ID.
>> Client sends its SID, the server find data.
>>
>> So... for example: If you test IP of the client and SID your can
>> secure the session from outside of the box but you can't do it with
>> inside of the box.
>>
>> Use SSL + check IP + never-never-ever store important information in
>> cookies.
>
> I am a bit confused now.
>
> For example, using the Opera browser, a user can check a cookie value. I
> understand that this value is used to identify a user, ie I can read it. But
> other people, on LAN or internet, cannot read it because when I send data,
> the data is enrcypted via https.
>
> I suppose the cookie value is the Session ID.
>

The cookie does not identify the user - it is just the session id.  What 
the server does with it is something else.

In general, the session id does identify the computer from which the 
cookie is being sent because the session id is a rather long 
pseudo-random alphanumeric value.  Yes it's possible for someone else to 
intercept and read the session id, but in general it's unlikely.

The real question is - what is the problem you are trying to resolve? 
If the data are that sensitive, you should be using a secure protocol 
for everything.  If the data aren't sensitive enough to require a secure 
protocol, why do you think the cookie is?




-- 
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@attglobal.net
==================

Back to comp.lang.php | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

session cookie: client side "sl@exabyte" <sb5309@hotmail.com> - 2011-11-03 17:10 +0800
  Re: session cookie: client side Balazs Nadasdi <yitsushi@gmail.com> - 2011-11-03 05:23 -0700
    Re: session cookie: client side "sl@exabyte" <ecp_gen@my-rialto.com> - 2011-11-04 14:14 +0800
      Re: session cookie: client side Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-04 07:55 -0400
        Re: session cookie: client side "sl@exabyte" <sb5309@hotmail.com> - 2011-11-04 22:21 +0800
          Re: session cookie: client side Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-04 14:40 -0400
        Re: session cookie: client side Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-04 15:53 +0000
          Re: session cookie: client side Jerry Stuckle <jstucklex@attglobal.net> - 2011-11-04 14:41 -0400
      Re: session cookie: client side Denis McMahon <denismfmcmahon@gmail.com> - 2011-11-04 15:52 +0000

csiph-web