Bug #17597 Updated: user supplied SID is given trust
| From: | Giancarlo at navigare dot net | Date: | Wed, 05 Jun 2002 18:15:11 +0000 |
| Subject: | Bug #17597 Updated: user supplied SID is given trust | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-9562@lists.php.net to get a copy of this message | ||
ID: 17597
Updated by: Giancarlo@navigare.net
Reported By: Giancarlo@navigare.net
Status: Open
Bug Type: Session related
PHP Version: 4.2.1
New Comment:
You know what? I know had a series ot test on zend site, ad it doesn't
quite work like this.
They must have a 'fortified' version of PHP there.
Previous Comments:
------------------------------------------------------------------------
[2002-06-05 13:13:21] Giancarlo@navigare.net
This hole does not need a cracker, but any computer illiterate, as my
or your boss, can do it.
Why do we use md5 of uniqid of secret words to generate a sid, when
anyone can force his own simply opening an URL?
------------------------------------------------------------------------
[2002-06-05 11:32:52] snowgod@snowgod.org
IMHO, fixing this does not solve the problem. If a cracker REALLY wants
to fake a session, he could fake the cookie as well.
Perhaps storing two seperate variable (either in the path, or in
cookies), a session id and a authentication hash of some kind. I would
think that this would make session spoofing lot harder, because the
cracker would have to guess both the correct session id, and the
correct authentication hash.
Just my 2 cents.
------------------------------------------------------------------------
[2002-06-04 11:50:24] Giancarlo@navigare.net
How is it possible that if a user provides a session in the URL, eg.
mypage.php?PHPSESSID=spoofme
even though php.ini says
session.use_cookies =1
The session id is taken from the URL (but wasn't that the supposed
behaviour of session.use_cookie=0 ?) and a session named 'spoofme' is
created.
Is it possible that is given trust to user input just on a paramount
sensitive issue as the session ID?
Would you run a cinema where you have to accept tickets issued by
nobody-knows-who?
This gravious security issue has been mentioned more than a year ago in
the 'A study in scarlet' classical on php weaknessses, and it leads to
nasty url injections and session hijacking.
I am afraid this bus is a great feature for someone.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=17597&edit=1