Bug #17597 Updated: user supplied SID is given trust
| From: | sniper@php.net | Date: | Wed, 05 Jun 2002 18:36:23 +0000 |
| Subject: | Bug #17597 Updated: user supplied SID is given trust | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-9567@lists.php.net to get a copy of this message | ||
ID: 17597
Updated by: sniper@php.net
Reported By: Giancarlo@navigare.net
-Status: Open
+Status: Bogus
Bug Type: Session related
PHP Version: 4.2.1
New Comment:
Sorry, but the bug system is not the appropriate forum for asking
support questions. Your problem does not imply a bug in PHP itself.
For a list of more appropriate places to ask for help using PHP,
please visit http://www.php.net/support.php
Thank you for your interest in PHP.
What use it would be to spoof the session id??
It only would make sense if you know what ids are currently
in use at the site. Of course you could always try the all
possible combinations there can be. :)
Previous Comments:
------------------------------------------------------------------------
[2002-06-05 14:15:11] Giancarlo@navigare.net
You know what? I know had a series ot test on zend site, ad it doesn't
quite work like this.
They must have a 'fortified' version of PHP there.
------------------------------------------------------------------------
[2002-06-05 13:13:21] Giancarlo@navigare.net
This hole does not need a cracker, but any computer illiterate, as my
or your boss, can do it.
Why do we use md5 of uniqid of secret words to generate a sid, when
anyone can force his own simply opening an URL?
------------------------------------------------------------------------
[2002-06-05 11:32:52] snowgod@snowgod.org
IMHO, fixing this does not solve the problem. If a cracker REALLY wants
to fake a session, he could fake the cookie as well.
Perhaps storing two seperate variable (either in the path, or in
cookies), a session id and a authentication hash of some kind. I would
think that this would make session spoofing lot harder, because the
cracker would have to guess both the correct session id, and the
correct authentication hash.
Just my 2 cents.
------------------------------------------------------------------------
[2002-06-04 11:50:24] Giancarlo@navigare.net
How is it possible that if a user provides a session in the URL, eg.
mypage.php?PHPSESSID=spoofme
even though php.ini says
session.use_cookies =1
The session id is taken from the URL (but wasn't that the supposed
behaviour of session.use_cookie=0 ?) and a session named 'spoofme' is
created.
Is it possible that is given trust to user input just on a paramount
sensitive issue as the session ID?
Would you run a cinema where you have to accept tickets issued by
nobody-knows-who?
This gravious security issue has been mentioned more than a year ago in
the 'A study in scarlet' classical on php weaknessses, and it leads to
nasty url injections and session hijacking.
I am afraid this bus is a great feature for someone.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=17597&edit=1