PHP 4.0 Bug #8189 Updated: storing sessions in world readable directory
| From: | sniper@php.net | Date: | Fri, 15 Dec 2000 14:56:41 +0000 |
| Subject: | PHP 4.0 Bug #8189 Updated: storing sessions in world readable directory | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-41467@lists.php.net to get a copy of this message | ||
ID: 8189
Updated by: sniper
Reported By: dig@cynosure.com
Status: Open
Old-Bug Type: *Session related
Bug Type: Documentation problem
Assigned To:
Comments:
Previous Comments:
---------------------------------------------------------------------------
[2000-12-09 23:37:32] dig@cynosure.com
By default, session files are stored in /tmp by default, unless changed by sessions.save_path.
Although the session files are not world-readable, the directory itself is, and any user on the
system can get a list of sessionids by just looking at the filenames. If sessions are being used to
track logins, a malicious user could hijack another person's login by copying his session-id
into a URI. This could present a serious security risk depending on the application's use of
sessions.
The simplest protection is to set sessions.save_path to a directory owned by the user PHP runs
under, and chmod 700 that directory. This prevents easy viewing of existing session IDs.
---------------------------------------------------------------------------
Full Bug description available at: http://bugs.php.net/?id=8189