#24781 [Opn->Fbk]: Security lapse due to flaw in session.use_only_cookies
| From: | sniper@php.net | Date: | Thu, 24 Jul 2003 03:13:33 +0000 |
| Subject: | #24781 [Opn->Fbk]: Security lapse due to flaw in session.use_only_cookies | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-44633@lists.php.net to get a copy of this message | ||
ID: 24781
Updated by: sniper@php.net
Reported By: spagmoid at yahoo dot com
-Status: Open
+Status: Feedback
Bug Type: Session related
Operating System: All
PHP Version: 4.3.2
New Comment:
Please try using this CVS snapshot:
http://snaps.php.net/php4-STABLE-latest.tar.gz
For Windows:
http://snaps.php.net/win32/php4-win32-STABLE-latest.zip
Previous Comments:
------------------------------------------------------------------------
[2003-07-23 19:20:57] spagmoid at yahoo dot com
Description:
------------
Our SID's have been leaking out today and becoming shared between 5+
users at once, causing massive corruption.
Our theory is that session.use_only_cookies does not always work. It
sometimes allows the SID to propagate in URL when cookies are disabled
(noticed in Netscape not IE for some reason).
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=24781&edit=1