Bug #71101 [Ana]: PHP Session Data Injection Vulnerability

From: Date: Sat, 27 Aug 2016 07:28:47 +0000
Subject: Bug #71101 [Ana]: PHP Session Data Injection Vulnerability
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203608@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71101&edit=1 ID: 71101 Updated by: yohgaki@php.net Reported by: taoguangchen at icloud dot com Summary: PHP Session Data Injection Vulnerability Status: Analyzed Type: Bug Package: Session related Operating System: * PHP Version: Irrelevant Block user comment: N Private report: N New Comment: In order to prevent this kind of mistake (Use of invalid serializer), we need to add some kind of signature in session data. Since the example code what switches serialize handler cannot work at all for normal usage, I'm not sure if mitigation is worth to have. Previous Comments: ------------------------------------------------------------------------ [2016-01-01 02:29:38] stas@php.net As this requires specific (and erroneous) user action to trigger, I don't think it is a security issue. I leave it open in case somebody has any ideas of how to prevent such mistake. ------------------------------------------------------------------------ [2015-12-29 02:01:00] stas@php.net That would be a big BC break (would break ZF code above for example) and also won't solve the problem completely as you could have different scripts (with different settings) use the same session. ------------------------------------------------------------------------ [2015-12-29 01:29:46] taoguangchen at icloud dot com Maybe you can consider change session.serialize_handler to PHP_INI_PERDIR. ------------------------------------------------------------------------ [2015-12-29 01:16:48] stas@php.net It is probably a bad idea to do this in conjunction with upload tracking feature, since it means upload tracking will access the session with wrong handler. I do not see however what can be done about it except telling people not to do it. Session module can not predict that somebody in the future would change a handler and try to load session data with wrong handler. ------------------------------------------------------------------------ [2015-12-29 01:06:44] taoguangchen at icloud dot com In fact, some frameworks or apps allow set serializer in mid-script. ex: zend framework https://github.com/zendframework/zend-session/blob/6d5557494e3e36df1e550314a6fcfde389993333/src/Config/SessionConfig.php#L172 https://github.com/zendframework/zend-session/blob/6d5557494e3e36df1e550314a6fcfde389993333/test/Config/SessionConfigTest.php#L211 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=71101 -- Edit this bug report at https://bugs.php.net/bug.php?id=71101&edit=1

« previous php.bugs (#203608) next »