Re: [users@httpd] Odd session cookies

2018-09-07 Thread Yehuda Katz
It looks like someone trying to guess existing cookies and retrieve session information for existing sessions. Based on the cookie format, I am guessing the sessions are actually controlled by PHP - you can add some code to log IP address and cookie combinations and see if there is a patterns. I

[users@httpd] Odd session cookies

2018-09-06 Thread John
Beginning last Sunday (2 September) I have been finding several oddly named session cookies each day on my server. The normal Apache session cookies have names like "sess_d50280ded90f1dbd48fcfd5fc77baa77". These new ones have names like: sess_mycustomsession sess_sessionidhere The content