Generate session IDs more securely

We now use a lot more data for generating the session id which is fed to a hash
to make it impossible to attack specific parts of the input.

Also we now retry generating a new session id in the (improbable) case of
collision with an existing session id.

Thanks a lot to cnu for pointing out the weakness in the old code by stealing my
session cookie, you evil hacker!


git-svn-id: https://znc.svn.sourceforge.net/svnroot/znc/trunk@1819 726aef4b-f618-498e-8847-2d620e286838
This commit is contained in:
psychon
2010-03-09 19:44:24 +00:00
parent 9036f5de74
commit cbb6e14c3a
2 changed files with 17 additions and 11 deletions
+3 -3
View File
@@ -34,7 +34,7 @@ private:
class CWebSession {
public:
CWebSession(const CString& sId = "");
CWebSession(const CString& sId);
virtual ~CWebSession() {}
const CString& GetId() const { return m_sId; }
@@ -135,14 +135,14 @@ public:
void PrintErrorPage(const CString& sMessage);
CSmartPtr<CWebSession> GetSession() const;
CSmartPtr<CWebSession> GetSession();
virtual Csock* GetSockObj(const CString& sHost, unsigned short uPort);
CString GetModWebPath(const CString& sModName) const;
CString GetSkinPath(const CString& sSkinName) const;
CModule* GetModule() const { return (CModule*) m_pModule; }
size_t GetAvailSkins(vector<CFile>& vRet);
CString GetSkinName() const;
CString GetSkinName();
CString GetCookie(const CString& sKey) const;
bool SetCookie(const CString& sKey, const CString& sValue);