Req #72744 [Opn]: https://wiki.php.net/rfc/session-id-without-hashing
| From: | cmb@php.net | Date: | Wed, 03 Aug 2016 16:01:20 +0000 |
| Subject: | Req #72744 [Opn]: https://wiki.php.net/rfc/session-id-without-hashing | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-202886@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72744&edit=1
ID: 72744
Updated by: cmb@php.net
Reported by: spam2 at rhsoft dot net
Summary: https://wiki.php.net/rfc/session-id-without-hashing
Status: Open
Type: Feature/Change Request
Package: Session related
PHP Version: Next Minor Version
-Assigned To:
+Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
Assigned to RFC author.
Previous Comments:
------------------------------------------------------------------------
[2016-08-03 14:09:51] spam2 at rhsoft dot net
Description:
------------
> Compatible defaults: session.sid_length=32, session.sid_bits_per_character=4
> (128 bits session ID. No BC break)
that is not true in case of smarter sysadmins which swicthed away from the MD5 default years ago and
hence in case the sesstings are present in "php.ini" it should change it's default
behavior to *really* be compatible
____________________________
session.entropy_length = 32
session.hash_function = 1
session.hash_bits_per_character = 6
SecRule REQUEST_COOKIES_NAMES|ARGS_NAMES
"(^PHPSESSID$|JSESSIONID$|ASPSESSIONID$|ASP\.NET_SessionId$)"
"id:'133',phase:2,capture,logdata:'%{TX.0}',block,msg:'Invalid
SessionID name not allowed'"
SecRule ARGS_NAMES
"(^LOUNGE_ID$|PANEL_ID$)""id:'134',phase:2,capture,logdata:'%{TX.0}',block,msg:'LOUNGE_ID
not allowed via GET or POST'"
SecRule REQUEST_COOKIES:LOUNGE_ID|REQUEST_COOKIES:PANEL_ID "!@rx ^[-a-z0-9,]{27}$"
"id:'135',phase:2,logdata:'%{matched_var}',t:urlDecodeUni,t:lowercase,block,msg:'Unexpected
value for LOUNGE_ID'"
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72744&edit=1