PHP 4.0 Bug #2580: Security issue with session IDs
| From: | jon at minotaur dot com | Date: | Thu, 21 Oct 1999 03:48:57 +0000 |
| Subject: | PHP 4.0 Bug #2580: Security issue with session IDs | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-11800@lists.php.net to get a copy of this message | ||
From: jon@minotaur.com
Operating system: Linux 2.0.12
PHP version: 4.0 Beta 1
PHP Bug Type: Misbehaving function
Bug description: Security issue with session IDs
There is a problem with PHP4 revision 2 in regards to session IDs.
Turn off cookie mode in your browser.
Change the session temp dir to somewhere else.
When the session ID comes up in your URL, remove the session id, and then add a bunch of ..'s.
For instance,
http://php.test.com/index.php?SESSIONID=../../../../tmp/test
This will overwrite the file name in that directory called "test". Though this does not
pose a high-risk security problem (due to the fact you'd have to know the file layout) unless
of course a doofus has apache running as root.
I guess Session management may need to be altered so it only accepts md5 hashes as a valid session,
bogus things such as ../../.. etc should be removed.