Bug #17597 Updated: user supplied SID is given trust

From: Date: Wed, 05 Jun 2002 18:15:11 +0000
Subject: Bug #17597 Updated: user supplied SID is given trust
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-9562@lists.php.net to get a copy of this message
ID: 17597 Updated by: Giancarlo@navigare.net Reported By: Giancarlo@navigare.net Status: Open Bug Type: Session related PHP Version: 4.2.1 New Comment: You know what? I know had a series ot test on zend site, ad it doesn't quite work like this. They must have a 'fortified' version of PHP there. Previous Comments: ------------------------------------------------------------------------ [2002-06-05 13:13:21] Giancarlo@navigare.net This hole does not need a cracker, but any computer illiterate, as my or your boss, can do it. Why do we use md5 of uniqid of secret words to generate a sid, when anyone can force his own simply opening an URL? ------------------------------------------------------------------------ [2002-06-05 11:32:52] snowgod@snowgod.org IMHO, fixing this does not solve the problem. If a cracker REALLY wants to fake a session, he could fake the cookie as well. Perhaps storing two seperate variable (either in the path, or in cookies), a session id and a authentication hash of some kind. I would think that this would make session spoofing lot harder, because the cracker would have to guess both the correct session id, and the correct authentication hash. Just my 2 cents. ------------------------------------------------------------------------ [2002-06-04 11:50:24] Giancarlo@navigare.net How is it possible that if a user provides a session in the URL, eg. mypage.php?PHPSESSID=spoofme even though php.ini says session.use_cookies =1 The session id is taken from the URL (but wasn't that the supposed behaviour of session.use_cookie=0 ?) and a session named 'spoofme' is created. Is it possible that is given trust to user input just on a paramount sensitive issue as the session ID? Would you run a cinema where you have to accept tickets issued by nobody-knows-who? This gravious security issue has been mentioned more than a year ago in the 'A study in scarlet' classical on php weaknessses, and it leads to nasty url injections and session hijacking. I am afraid this bus is a great feature for someone. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=17597&edit=1

« previous php.bugs (#9562) next »