Bug #69073 [Nab]: SESSION is corrupt
| From: | martin dot schmitz at uni-bielefeld dot de | Date: | Thu, 19 Feb 2015 08:21:31 +0000 |
| Subject: | Bug #69073 [Nab]: SESSION is corrupt | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-190800@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69073&edit=1
ID: 69073
User updated by: martin dot schmitz at uni-bielefeld dot de
Reported by: martin dot schmitz at uni-bielefeld dot de
Summary: SESSION is corrupt
Status: Not a bug
Type: Bug
Package: Session related
Operating System: Linux / Mageia
PHP Version: 5.6Git-2015-02-18 (Git)
Block user comment: N
Private report: N
New Comment:
> "You should mention that to the people who design the HTTP standard."
- What does HTTP standard has to do with PHP-session-handling?
> "What are your session.* INI settings? Specifically session.use_only_cookies."
- See http://test.rtin.ws (phpinfo() is now included,
session.use_only_cookies is "on")
> "It's definitely risky..."
- Security discussion has not to be in bug-reporting.
> "Which is why PHP doesn't use that behavior unless you go out of your way to enable
> it."
- Yep, and then this bug occures.
> "You can say that all you want, it doesn't change the technical problem:"
- That's the point, so please, don't have a look to my favoutity settings or security
risks: Please fix the technical problem.
> "without the URL or a cookie, PHP can't know which session to use for a request. Or
> maybe you have a suggestion for how to do that?"
- if PHP sets a cookie, session-request will be read from there.
- if you don't use "session_name();" PHP is looking for $_REQUEST[PHPSESSID]
- if you use "session_name('my_name');" PHP is looking for
$_REQUEST['my_name']
All in all: in previous versions session handling always worked in this constallation (as I wrote,
somewhere in PHP4 this error occured too). You can use my simple script to test it for yourself.
I don't want to discuss any longer this weird cookie/security stuff. For me I have a workaround
(setting session_id() manually) and 99% won't recognize this bug, because they have cookies
activated.
This is clearly a technical bug in PHP-session handling (a friend of mine tested it with his own
server and the same error occures, and I bet, that if you try it on your own server, it will occure
too).
A security discussion does not fix this bug.
Previous Comments:
------------------------------------------------------------------------
[2015-02-19 07:14:12] requinix@php.net
>It's a bug, because session-handling does not work as it should.
You should mention that to the people who design the HTTP standard. Make sure you CC the developers
of browsers so that they know not to allow users to change configuration settings that may break
your website.
>It's a bug, because, if you set session_id($_REQUSET[PHPSESSID])) manually, it
>works.
What are your session.* INI settings? Specifically session.use_only_cookies.
>If it is a risk to send the session per URL, it shouldn't be possible to do
>this at all
It's definitely risky. Which is why PHP doesn't use that behavior unless you go out of
your way to enable it.
>It's not right IMHO to force a user to set cookies
You can say that all you want, it doesn't change the technical problem: without the URL or a
cookie, PHP can't know which session to use for a request. Or maybe you have a suggestion for
how to do that?
------------------------------------------------------------------------
[2015-02-19 06:57:21] martin dot schmitz at uni-bielefeld dot de
Sorry, but this answer is a bit "stupid":
- It's a bug, because session-handling does not work as it should.
- It's a bug, because, if you set session_id($_REQUSET[PHPSESSID])) manually, it works.
- If it is a risk to send the session per URL, it shouldn't be possible to do this at all (any
hacker knows, how to handle cookies, even it's described other way in the documentation).
- It's not right IMHO to force a user to set cookies (I don't like them, and it worries
me, if a page forces me to use them. Same for javascript.). My pages should work in every case.
So if you want to see this effect: http://test.rtin.ws
BTW. this error occured a few yeas ago (somewhere in PHP 4).
Workaround: Set session_id() manually.
But it's still a bug
------------------------------------------------------------------------
[2015-02-18 19:28:31] requinix@php.net
Sessions are generally persisted using cookies so this should be an obvious side-effect of disabling
them.
If this is a problem for your application, one common solution (besides telling your user to enable
cookies) is to put the session ID in the URL unless/until you've detected that cookies are
enabled. Which is risky. See also the session.use-trans-sid* INI setting where PHP will
automatically rewrite the URLs for you.
* http://php.net/manual/en/session.configuration.php#ini.session.use-trans-sid
------------------------------------------------------------------------
[2015-02-18 12:28:20] martin dot schmitz at uni-bielefeld dot de
Description:
------------
Session (SID) generates always an new id, when cookies are disabled (PHP Version 5.6.0)
Test script:
---------------
<?php
session_name('test');
session_start();
echo '<a href="?'.SID.'">test</a>'
?>
Expected result:
----------------
constant id, if no timeout kills session
Actual result:
--------------
always new id
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69073&edit=1