Sec Bug->Req #66947 [Opn]: Session fixation with use_strict_mode on custom save handlers
| From: | stas@php.net | Date: | Mon, 24 Mar 2014 18:34:04 +0000 |
| Subject: | Sec Bug->Req #66947 [Opn]: Session fixation with use_strict_mode on custom save handlers | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-184868@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66947&edit=1
ID: 66947
Updated by: stas@php.net
Reported by: ondrej dot machulda at gmail dot com
Summary: Session fixation with use_strict_mode on custom save
handlers
Status: Open
-Type: Security
+Type: Feature/Change Request
Package: Session related
PHP Version: 5.5.10
Block user comment: N
Private report: Y
New Comment:
I would think this is for save handler authors to implement necessary code to support
user_strict_mode. If you have an idea how to improve the functionality, you're welcome to
submit pull/RFC, however I do not think that if some custom handler does not implement this
capability this implies a security bug in PHP.
Previous Comments:
------------------------------------------------------------------------
[2014-03-24 15:52:38] ondrej dot machulda at gmail dot com
Description:
------------
PHP 5.5.2 introduced session.use_strict_mode settings, which, if enabled, rejects uninitialized
session IDs provided by the client and regenerate the SID with a new one. This protect user from one
kind of session fixation attack, see CVE-2011-4718
The manual states:
session.use_strict_mode specifies whether the module will use strict session id mode. If this mode
is enabled, the module does not accept uninitialized session ID. If uninitialized session ID is sent
from browser, new session ID is sent to browser. Applications are protected from session fixation
via session adoption with strict mode. Defaults to 0 (disabled).
However, the strict mode is only implemented in mod_files
(https://github.com/php/php-src/search?q=use_strict_mode&type=Code), thus using any custom
session save handler (for eg. memcache, redis, database...) will keep you with this vulnerability
exploitable.
I see two problems there:
1) The configuration option may confuse you to think you are protected (no matter the session save
handler you use), what is apparently not true.
2) IMHO the strict mode could be done handler-agnostic, for example modifying
SessionHandlerInterface to require validate() method or something.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66947&edit=1