Skip to content
View in the app

A better way to browse. Learn more.

Web Designer Forum

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

SESSION Hijacking

Featured Replies

Hello all. I'm a bit of a PHP noob, especially when it comes to security, so I've been lurking around the web looking at a bunch of articles that talk of some do's and dont's when considering making your PHP-driven website secure. Among the many security concerns there are two that call to my attention. Session Hijacking and SQL Insertion. I'm worried about the former because I pass some variables into a session, however, these variables do not contain any critical data, the only contain error messages. Here's a snippet:

 

// Make sure the user selected atleast one item...
if(empty($selection)) {
	$err[] = "ERROR - You did not select anything to delete.";
	$_SESSION["errors"] = $err;
	header("Location: img_del.php?doAction=delete&doCheck=failed");
	exit();
}

// Display Error Messages
if($_GET["doCheck"] == "failed") { // Post errors, if any...
	echo "<p class=\"error\">";
	foreach($_SESSION["errors"] as $key=>$e) { echo "* $e <br />"; }
	echo "</p>";
	unset($_SESSION["errors"]); // unset the error variable...
}

 

I'm aware of some preventive measures that can be taken to avoid session hijacking, however, should I regenerate the session id even if the data contained in the session is non-critical? Can the snippet above be exploited in any way?

 

As for the latter, SQL Injection, while searching the web for common security techniques I stumbled across a useful function that filters the input data from a form:

 

/*
This code filters harmful script code and escapes data of all POST data
from the user submitted form.
*/
function filter($data) {
$data = trim(htmlentities(strip_tags($data)));
if(get_magic_quotes_gpc())
	$data = stripslashes($data);
	$data = mysql_real_escape_string($data);
return $data;
}

// Loop through input values and filter...
foreach($_POST as $key => $value) { $data[$key] = filter($value); }

 

Since the filter function is using mysql_real_escape_string to filter the data when querying the DB, I don't really take any other security measures afterwards. Is it bad practice to assign $data["input"] straight to a variable to be later used when querying the DB?

 

Thanks in advance for any tips given!

Edited by larsson719

1 - No, data in the session is set by the server not the client so if its just strings then you don't need to worry about session hijacking. You'd only worry about that kind of stuff if you had a secure area where a hijacker could intercept the session id and access the secure area. If that is the case then there are techniques to regenerate the session, checking things like user agent, IP, country, etc.

 

2 - I will probably get shot down on here again for suggesting this but unless you know what your doing you shouldn't use the ancient mysql functions like mysql_real_escape_string, you should use PDO and prepared statements as they are immune to SQL injection - http://www.php.net/manual/en/pdostatement.bindvalue.php

 

3 - Obviously you will still want to filter your data (e.g prevent an invalid email address) for this use the native filter functions - http://php.net/manual/en/book.filter.php

 

Also don't use Magic Quotes. Turn it off on your server, its deprecated as of PHP5.3 - http://php.net/manual/en/security.magicquotes.php

I think jock has covered all bases :), and I must say I tend to opt for the mysql_real_escape_string/mysql_escape_string for most applications (one of us had to say it :p ) but this really depends on the level of security the application requires but as said each to their own.

 

Somewhat of a commonly overlooked and simple solution that short of cross-site scripting attacks or gaining access to the client PC, is SSL. At around £15/35 a year It is worth the investment and must be noted as it is being used much more widely now.

 

My personal opinion is that SSL should be used on any site that requires a login and or personal/private data, simply because these days anyone, especially in/on public/work/college/university networks can simply monitor the packets and pickup your password, username or data in transit.

 

An example of this that always springs to mind was that of a test carried out at the university I attend, In which a wireless network was enabled in an on campus location by the IT staff and selected students under the BSC Hons for forensic computing.

 

It was enabled for precisely 1 hour and no data was recorded, additionally the computer formatted and data onscreen was filtered (hashed),however within that period if memory serves me near 300 separate username/password combinations as well as 30 full credit/debit card details were seen which is rather shocking.

 

Equality the same could be done via a laptop gaining access to your home wireless at an extreme end of the scale. Like all security fixes and precautions it certainly is another more intimidating obstacle than can be put in the way of possible attacks.

Note - You must ensure that cookies are sent only via SSL in if you where to use SSL

Edited by CSN-UK

  • Author

Thanks for pointing out the PDO extension, jock, I was not aware that this existed :o but it seems like a more secure alternative.

 

I think jock has covered all bases :), and I must say I tend to opt for the mysql_real_escape_string/mysql_escape_string for most applications (one of us had to say it :p ) but this really depends on the level of security the application requires but as said each to their own.

 

I will look into SSL as I'm planning on setting up a small e-commerce system as well--meaning there will be some sensitive data being sent through the system. Perhaps with SSL, it can make up for any lack of security I may have in the system... although I will try to patch up as many security holes as possible.

Edited by larsson719

Create an account or sign in to comment

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.