Bug #71101 [Com]: PHP Session Data Injection Vulnerability

From: Date: Wed, 09 Nov 2016 00:10:52 +0000
Subject: Bug #71101 [Com]: PHP Session Data Injection Vulnerability
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205249@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71101&edit=1

 ID:                 71101
 Comment by:         love at sickpeople dot se
 Reported by:        taoguangchen at icloud dot com
 Summary:            PHP Session Data Injection Vulnerability
 Status:             Analyzed
 Type:               Bug
 Package:            Session related
 Operating System:   *
 PHP Version:        Irrelevant
 Block user comment: N
 Private report:     N

 New Comment:

What about adding a warning when the serialize handler is changed?

If telling people about it is the option here, it should be done with a warning (ie actively). Or a
E_NOTICE since it's strictly not an error.


Previous Comments:
------------------------------------------------------------------------
[2016-08-27 07:29:50] yohgaki@php.net

s/what/that/

------------------------------------------------------------------------
[2016-08-27 07:28:46] yohgaki@php.net

In order to prevent this kind of mistake (Use of invalid serializer), we need to add some kind of
signature in session data. 

Since the example code what switches serialize handler cannot work at all for normal usage, I'm
not sure if mitigation is worth to have.

------------------------------------------------------------------------
[2016-01-01 02:29:38] stas@php.net

As this requires specific (and erroneous) user action to trigger, I don't think it is a
security issue. I leave it open in case somebody has any ideas of how to prevent such mistake.

------------------------------------------------------------------------
[2015-12-29 02:01:00] stas@php.net

That would be a big BC break (would break ZF code above for example) and also won't solve the
problem completely as you could have different scripts (with different settings) use the same
session.

------------------------------------------------------------------------
[2015-12-29 01:29:46] taoguangchen at icloud dot com

Maybe you can consider change session.serialize_handler to PHP_INI_PERDIR.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=71101


--
Edit this bug report at https://bugs.php.net/bug.php?id=71101&edit=1


Thread (1 message)

  • love at sickpeople dot se
  • Unknown Message
    • love at sickpeople dot se
« previous php.bugs (#205249) next »