PHP 4.0 Bug #8184: session security bug(?)

From: Date: Sat, 09 Dec 2000 17:34:17 +0000
Subject: PHP 4.0 Bug #8184: session security bug(?)
Groups: php.dev 
Request: Send a blank email to php-dev+get-40664@lists.php.net to get a copy of this message
From: zeles@freemail.hu Operating system: Slackware 7.0 PHP version: 4.0.3pl1 PHP Bug Type: *Session related Bug description: session security bug(?) Hi! A part of my php.ini looks like this: session.gc_probability = 100 session.gc_maxlifetime = 0 session.cache_limiter = nocache session.use_cookies = 0 session.auto_start = 0 session.use_trans_sid = 1 session.cookie_lifetime = 0 The situation: the client cuts the URL of the actual page to the clipboard (the URL contains the session-id) and close the browser. The session file becomes garbage and it will be collected at the next session call - I thought. However, when the client opens the browser and pastes the URL into the address line - and there isn't any other session call from another client - PHP lets him in. If the URL does not contain the session-id everything works fine: the garbage collector collects all of the garbage. Summary: if the session_start() gets session-id by GET parameter or by a cookie, it doesn't check whether the session file is garbage or not. I think it's a minor security bug. Thanks Zoltan Eles -- Edit Bug report at: http://bugs.php.net/?id=8184&edit=1

« previous php.dev (#40664) next »