Req #72744 [Opn]: https://wiki.php.net/rfc/session-id-without-hashing

From: Date: Wed, 03 Aug 2016 16:01:20 +0000
Subject: Req #72744 [Opn]: https://wiki.php.net/rfc/session-id-without-hashing
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202886@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72744&edit=1 ID: 72744 Updated by: cmb@php.net Reported by: spam2 at rhsoft dot net Summary: https://wiki.php.net/rfc/session-id-without-hashing Status: Open Type: Feature/Change Request Package: Session related PHP Version: Next Minor Version -Assigned To: +Assigned To: yohgaki Block user comment: N Private report: N New Comment: Assigned to RFC author. Previous Comments: ------------------------------------------------------------------------ [2016-08-03 14:09:51] spam2 at rhsoft dot net Description: ------------ > Compatible defaults: session.sid_length=32, session.sid_bits_per_character=4 > (128 bits session ID. No BC break) that is not true in case of smarter sysadmins which swicthed away from the MD5 default years ago and hence in case the sesstings are present in "php.ini" it should change it's default behavior to *really* be compatible ____________________________ session.entropy_length = 32 session.hash_function = 1 session.hash_bits_per_character = 6 SecRule REQUEST_COOKIES_NAMES|ARGS_NAMES "(^PHPSESSID$|JSESSIONID$|ASPSESSIONID$|ASP\.NET_SessionId$)" "id:'133',phase:2,capture,logdata:'%{TX.0}',block,msg:'Invalid SessionID name not allowed'" SecRule ARGS_NAMES "(^LOUNGE_ID$|PANEL_ID$)""id:'134',phase:2,capture,logdata:'%{TX.0}',block,msg:'LOUNGE_ID not allowed via GET or POST'" SecRule REQUEST_COOKIES:LOUNGE_ID|REQUEST_COOKIES:PANEL_ID "!@rx ^[-a-z0-9,]{27}$" "id:'135',phase:2,logdata:'%{matched_var}',t:urlDecodeUni,t:lowercase,block,msg:'Unexpected value for LOUNGE_ID'" ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72744&edit=1

« previous php.bugs (#202886) next »