Bogk "warns that, despite recent PHP improvements, the session IDs of users who are logged into PHP applications remain guessable," The H reported.
The problem is that PHP developers are seeding their random generator with a call to the "gettimeofday" function.
Read the whole story: http://www.developer.com/daily_news/article.php/396686/PHP-Session-IDs-Are-Guessable.htm