Bug #17597: user supplied SID is given trust
| From: | Giancarlo at navigare dot net | Date: | Tue, 04 Jun 2002 15:50:24 +0000 |
| Subject: | Bug #17597: user supplied SID is given trust | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-9476@lists.php.net to get a copy of this message | ||
From: Giancarlo@navigare.net
Operating system:
PHP version: 4.2.1
PHP Bug Type: Session related
Bug description: user supplied SID is given trust
How is it possible that if a user provides a session in the URL, eg.
mypage.php?PHPSESSID=spoofme
even though php.ini says
session.use_cookies =1
The session id is taken from the URL (but wasn't that the supposed
behaviour of session.use_cookie=0 ?) and a session named 'spoofme' is
created.
Is it possible that is given trust to user input just on a paramount
sensitive issue as the session ID?
Would you run a cinema where you have to accept tickets issued by
nobody-knows-who?
This gravious security issue has been mentioned more than a year ago in
the 'A study in scarlet' classical on php weaknessses, and it leads to
nasty url injections and session hijacking.
I am afraid this bus is a great feature for someone.
--
Edit bug report at http://bugs.php.net/?id=17597&edit=1
--
Fixed in CVS: http://bugs.php.net/fix.php?id=17597&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=17597&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=17597&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=17597&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=17597&r=support
Expected behavior: http://bugs.php.net/fix.php?id=17597&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=17597&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=17597&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=17597&r=globals