Sec Bug->Req #67798 [Opn->Nab]: Handling possible collisions of session ID
| From: | stas@php.net | Date: | Tue, 30 Dec 2014 09:04:36 +0000 |
| Subject: | Sec Bug->Req #67798 [Opn->Nab]: Handling possible collisions of session ID | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-189343@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67798&edit=1
ID: 67798
Updated by: stas@php.net
Reported by: jan dot kahoun at heureka dot cz
Summary: Handling possible collisions of session ID
-Status: Open
+Status: Not a bug
-Type: Security
+Type: Feature/Change Request
Package: Session related
Operating System: irrelevant
PHP Version: Irrelevant
Block user comment: N
Private report: Y
New Comment:
As you mentioned, you can use SessionHandler::create_sid for this.
Previous Comments:
------------------------------------------------------------------------
[2014-09-02 09:06:26] jan dot kahoun at heureka dot cz
Could anyone look at this issue, please?
------------------------------------------------------------------------
[2014-08-06 14:34:54] jan dot kahoun at heureka dot cz
Description:
------------
Hi,
we are using MySQL for storing sessions of logged-in users and we've
encountered a problem with few duplicated sessions ID when inserting new one
during last year. We've looked into PHP source code where we found a possible
bug.
Currently we are using PHP 5.4.29, so we investigated source code for this
version at first (file ext/session/session.c, function
php_session_initialize). We've found out that after the new session ID is
created, it is not checked if it exists in session storage. Then this new
session ID is used to read data from session storage. This could lead to
reading data of another user if duplicated session ID was generated.
The possibility of ID collision is small, but could happen and for our case
already happened. We currently have ~500k active sessions with ~30k new
sessions per day.
Also we looked into source code of PHP 5.5.15. The problem persists int this
version too. But now there is possible workaround. SessionHandler and
SessionHandlerInterface have a new method for creating own session ID, but it
is not mentioned in documentation. This method was not build to handle this
problem, but can be used for it.
Possible solution:
Create method in PHP like "testAndCreate" in SessionHandler and
SessionHandlerInterface which should check if session ID exists in session
storage and if not create it. Depending on the result PHP should generate new
ID or continue. Also mention this in documentation.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67798&edit=1