diff options
Diffstat (limited to 'engine/lib/sessions.php')
-rw-r--r-- | engine/lib/sessions.php | 23 |
1 files changed, 22 insertions, 1 deletions
diff --git a/engine/lib/sessions.php b/engine/lib/sessions.php index c6ae6f8d4..0a35fec1a 100644 --- a/engine/lib/sessions.php +++ b/engine/lib/sessions.php @@ -162,6 +162,13 @@ session_destroy();
return true;
+ } + + function get_session_fingerprint() + { + global $CONFIG; + + return md5($_SERVER['HTTP_USER_AGENT'] ); }
/**
@@ -182,7 +189,21 @@ if (!is_db_installed()) return false;
session_name('Elgg');
- session_start();
+ session_start(); + + // Do some sanity checking by generating a fingerprint (makes some XSS attacks harder) + if (isset($_SESSION['__elgg_fingerprint'])) + { + if ($_SESSION['__elgg_fingerprint'] != get_session_fingerprint()) + { + session_destroy(); + return false; + } + } + else + { + $_SESSION['__elgg_fingerprint'] = get_session_fingerprint(); + } if (empty($_SESSION['guid'])) {
if (isset($_COOKIE['elggperm'])) {
|