Cookieless Session Hacking - Prevention?
We were discussing some of the issues related to cookieless sessions, which "munge" the session id onto the url in ASP.NET. Obviously, this is not exactly the most secure method to pass around session ids.
We were discussing some of the issues related to cookieless sessions, which "munge"
the session id onto the url in ASP.NET. Obviously, this is not exactly the most
secure method to pass around session ids.
A solution : create a
hash value that incorporates the session id and information specific to the client.
If we take the session id and the IP address of the user and combine
them in a string, the result would be like so:
Y1EF3PRPX44QICWLEALCFFA;207.216.122.240
If you hash this string using MD5 encryption, the result would
look like this:
5bf69b3bbcc1f43ba5169597a1b72dd8
To validate
the user/session, all you need to do is retrieve the user's IP address and the
session id.
Then you would generate a new hash and compare it to the hash
you originally created. If they don’t match, either it is a new session or
someone is trying to hijack another user’s session (because the session ID
would match, but not the IP address, or vice versa). Otherwise, the user is "legit".
Note that this is completely different from and over-and-above whatever authentication
method
you may be using to allow users to "log in" in the first
place.
Here is some server-side code to retrieve the IP address
and the session ID for a user:
string IPAddress= Request.ServerVariables
["REMOTE_ADDR"];
string SessID = Session.SessionID;
Reader
David Prothero mentions that using the IP address won’t work for users on a
network that uses load-balanced proxy servers or other mechanisms that would
cause their IP address to be different for each request. This is common on AOL,
for example.
Perhaps something that would work a little more universally
is just the first two octets of the IP address (since those don’t tend to vary
in the above scenario) and combine it with the User-Agent from the headers (which
would also remain constant).
Submission Date: 9/23/2005
3:17:42 PM
Submitted By: Peter Bromberg
My Home Page: http://www.eggheadcafe.com
By Peter Bromberg Popularity (907 Views)