PHP 4.0 Bug #8184: session security bug(?)
| From: | zeles at freemail dot hu | Date: | Sat, 09 Dec 2000 17:34:17 +0000 |
| Subject: | PHP 4.0 Bug #8184: session security bug(?) | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-40664@lists.php.net to get a copy of this message | ||
From: zeles@freemail.hu
Operating system: Slackware 7.0
PHP version: 4.0.3pl1
PHP Bug Type: *Session related
Bug description: session security bug(?)
Hi!
A part of my php.ini looks like this:
session.gc_probability = 100
session.gc_maxlifetime = 0
session.cache_limiter = nocache
session.use_cookies = 0
session.auto_start = 0
session.use_trans_sid = 1
session.cookie_lifetime = 0
The situation:
the client cuts the URL of the actual page to the clipboard (the URL contains the session-id) and
close the browser.
The session file becomes garbage and it will be collected at the next session call - I thought.
However, when the client opens the browser and pastes the URL into the address line - and there
isn't any other session call from another client - PHP lets him in.
If the URL does not contain the session-id everything works fine: the garbage collector collects all
of the garbage.
Summary: if the session_start() gets session-id by GET parameter or by a cookie, it doesn't
check whether the session file is garbage or not.
I think it's a minor security bug.
Thanks
Zoltan Eles
--
Edit Bug report at: http://bugs.php.net/?id=8184&edit=1