Bug #17597 Updated: user supplied SID is given trust

From: Date: Wed, 05 Jun 2002 18:36:23 +0000
Subject: Bug #17597 Updated: user supplied SID is given trust
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-9567@lists.php.net to get a copy of this message
ID: 17597 Updated by: sniper@php.net Reported By: Giancarlo@navigare.net -Status: Open +Status: Bogus Bug Type: Session related PHP Version: 4.2.1 New Comment: Sorry, but the bug system is not the appropriate forum for asking support questions. Your problem does not imply a bug in PHP itself. For a list of more appropriate places to ask for help using PHP, please visit http://www.php.net/support.php Thank you for your interest in PHP. What use it would be to spoof the session id?? It only would make sense if you know what ids are currently in use at the site. Of course you could always try the all possible combinations there can be. :) Previous Comments: ------------------------------------------------------------------------ [2002-06-05 14:15:11] Giancarlo@navigare.net You know what? I know had a series ot test on zend site, ad it doesn't quite work like this. They must have a 'fortified' version of PHP there. ------------------------------------------------------------------------ [2002-06-05 13:13:21] Giancarlo@navigare.net This hole does not need a cracker, but any computer illiterate, as my or your boss, can do it. Why do we use md5 of uniqid of secret words to generate a sid, when anyone can force his own simply opening an URL? ------------------------------------------------------------------------ [2002-06-05 11:32:52] snowgod@snowgod.org IMHO, fixing this does not solve the problem. If a cracker REALLY wants to fake a session, he could fake the cookie as well. Perhaps storing two seperate variable (either in the path, or in cookies), a session id and a authentication hash of some kind. I would think that this would make session spoofing lot harder, because the cracker would have to guess both the correct session id, and the correct authentication hash. Just my 2 cents. ------------------------------------------------------------------------ [2002-06-04 11:50:24] Giancarlo@navigare.net How is it possible that if a user provides a session in the URL, eg. mypage.php?PHPSESSID=spoofme even though php.ini says session.use_cookies =1 The session id is taken from the URL (but wasn't that the supposed behaviour of session.use_cookie=0 ?) and a session named 'spoofme' is created. Is it possible that is given trust to user input just on a paramount sensitive issue as the session ID? Would you run a cinema where you have to accept tickets issued by nobody-knows-who? This gravious security issue has been mentioned more than a year ago in the 'A study in scarlet' classical on php weaknessses, and it leads to nasty url injections and session hijacking. I am afraid this bus is a great feature for someone. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=17597&edit=1

« previous php.bugs (#9567) next »