A
A. Sinan Unur
(e-mail address removed) wrote in @c13g2000cwb.googlegroups.com:
Thank you for pointing that out. I am not sure exactly what this means for
the validity of using MD5 for session keys, but it is good to keep in mind.
You are missing the point of session hijacking.
http://userpages.umbc.edu/~mabzug1/cs/md5/md5.html
The unofficial MD5 home page has information on collision weakness of
MD5.
Thank you for pointing that out. I am not sure exactly what this means for
the validity of using MD5 for session keys, but it is good to keep in mind.
to ensure a unique value for the session id, it would seem that
querying the database table of session ids to ensure that a new id is
unique prior to entering it in the table would be a good idea.
You are missing the point of session hijacking.