PHP 4.0 Bug #8189: storing sessions in world readable directory

From: Date: Sun, 10 Dec 2000 04:37:32 +0000
Subject: PHP 4.0 Bug #8189: storing sessions in world readable directory
Groups: php.dev 
Request: Send a blank email to php-dev+get-40728@lists.php.net to get a copy of this message
From: dig@cynosure.com Operating system: Linux PHP version: 4.0.3pl1 PHP Bug Type: *Session related Bug description: storing sessions in world readable directory By default, session files are stored in /tmp by default, unless changed by sessions.save_path. Although the session files are not world-readable, the directory itself is, and any user on the system can get a list of sessionids by just looking at the filenames. If sessions are being used to track logins, a malicious user could hijack another person's login by copying his session-id into a URI. This could present a serious security risk depending on the application's use of sessions. The simplest protection is to set sessions.save_path to a directory owned by the user PHP runs under, and chmod 700 that directory. This prevents easy viewing of existing session IDs. -- Edit Bug report at: http://bugs.php.net/?id=8189&edit=1

« previous php.dev (#40728) next »