Sec Bug->Req #67798 [Opn->Nab]: Handling possible collisions of session ID

From: Date: Tue, 30 Dec 2014 09:04:36 +0000
Subject: Sec Bug->Req #67798 [Opn->Nab]: Handling possible collisions of session ID
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189343@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67798&edit=1 ID: 67798 Updated by: stas@php.net Reported by: jan dot kahoun at heureka dot cz Summary: Handling possible collisions of session ID -Status: Open +Status: Not a bug -Type: Security +Type: Feature/Change Request Package: Session related Operating System: irrelevant PHP Version: Irrelevant Block user comment: N Private report: Y New Comment: As you mentioned, you can use SessionHandler::create_sid for this. Previous Comments: ------------------------------------------------------------------------ [2014-09-02 09:06:26] jan dot kahoun at heureka dot cz Could anyone look at this issue, please? ------------------------------------------------------------------------ [2014-08-06 14:34:54] jan dot kahoun at heureka dot cz Description: ------------ Hi, we are using MySQL for storing sessions of logged-in users and we've encountered a problem with few duplicated sessions ID when inserting new one during last year. We've looked into PHP source code where we found a possible bug. Currently we are using PHP 5.4.29, so we investigated source code for this version at first (file ext/session/session.c, function php_session_initialize). We've found out that after the new session ID is created, it is not checked if it exists in session storage. Then this new session ID is used to read data from session storage. This could lead to reading data of another user if duplicated session ID was generated. The possibility of ID collision is small, but could happen and for our case already happened. We currently have ~500k active sessions with ~30k new sessions per day. Also we looked into source code of PHP 5.5.15. The problem persists int this version too. But now there is possible workaround. SessionHandler and SessionHandlerInterface have a new method for creating own session ID, but it is not mentioned in documentation. This method was not build to handle this problem, but can be used for it. Possible solution: Create method in PHP like "testAndCreate" in SessionHandler and SessionHandlerInterface which should check if session ID exists in session storage and if not create it. Depending on the result PHP should generate new ID or continue. Also mention this in documentation. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67798&edit=1

« previous php.bugs (#189343) next »