Req #65746 [Asn]: session_regenerate_id() should not delete old session data immediately.

From: Date: Thu, 31 May 2018 11:51:47 +0000
Subject: Req #65746 [Asn]: session_regenerate_id() should not delete old session data immediately.
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-215453@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=65746&edit=1

 ID:                 65746
 Updated by:         yohgaki@php.net
 Reported by:        yohgaki@php.net
 Summary:            session_regenerate_id() should not delete old
                     session data immediately.
 Status:             Assigned
 Type:               Feature/Change Request
 Package:            Session related
 PHP Version:        5.5Git-2013-09-23 (Git)
 Assigned To:        yohgaki
 Block user comment: N
 Private report:     N

 New Comment:

Precisely, there are 2 issues;

 1. session_regenerate_id() will not delete/invalidate old data.
 2. session_regenerate_id(true) deletes data immediately.

1. allows attackers to abuse hijacked sessions safely(undetected) and freely(keep it as long as they
want).
2. causes race condition that results in lost sessions.


Previous Comments:
------------------------------------------------------------------------
[2018-05-31 11:34:32] yohgaki@php.net

It's not about $_SESSION, but old session data stored in session storage.

Anyway, my bug description was incorrect.

bool session_regenerate_id ([ bool $delete_old_session = FALSE ] )

$delete_old_session option deletes session data from the session storage immediately, but it should
eventually delete old session data. i.e. It should make old session data inaccessible after a while
by keeping track expiration time stamp to avoid and detect hijacked sessions.

Immediate session data deletion will cause race condition that is very hard to debug also. e.g. Few
lost sessions with tens of millions requests per day.

Current behavior and design is wrong. I created 2 RFCs to fix this design bug. I shall write 3rd RFC
in the future.

------------------------------------------------------------------------
[2018-05-31 09:01:36] tony at marston-home dot demon dot co dot uk

session_regenerate_id() was never meant to destroy the session data, that is what unset($_SESSION)
is for. Not even session_destroy() will delete the $_SESSION array, which means that it can be
reused with the next call to session_start().

It is perfectly legitimate to open a session with one id, thus obtaining the $_SESSION array, then
to use session_regenerate_id() to change the session_id() so that it can be saved under the new id.
Any scripts still using the previous session_id() will still work. While both sessions start off
with copies of the same $_SESSION array, these copies can quickly diverge because they are different
copies being accessed with different ids.

------------------------------------------------------------------------
[2016-10-17 06:38:05] yohgaki@php.net

Use proper title. Original title meant "no deletion by __default__".
Last RFC is declined, but we _MUST_ fix this issue.

session_regenerate_id() depreciation is a option. We shouldn't keep security related broken
function.

------------------------------------------------------------------------
[2015-09-29 02:07:59] yohgaki@php.net

Related RFC
https://wiki.php.net/rfc/precise_session_management

------------------------------------------------------------------------
[2015-07-11 20:45:00] ab@php.net

Related To: Bug #70013

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=65746


--
Edit this bug report at https://bugs.php.net/bug.php?id=65746&edit=1


Thread (20 messages)

« previous php.bugs (#215453) next »