Workaround against session spoofing and session gc

From: Date: Sat, 02 Feb 2002 16:00:54 +0000
Subject: Workaround against session spoofing and session gc
References: 1 2 3  Groups: php.dev 
Request: Send a blank email to php-dev+get-78898@lists.php.net to get a copy of this message
Hi,

    I have a question about your suggested workaround on
http://www.securiteam.com/unixfocus/5AP0A1F61Q.html
:


> And make sure to take away "r". r means "listing a directory". Apache only
> has to be able to "go into it" = x = 1, and "write" = w = 2. 1 + 2 = 3, so
>
>   chmod 300 php_sessions
>
> Now, although apache is able to create and read sessions, it is not anymore possible to list
> the directory.
>

I'm agree that's the right way to avoid id reading from any php scripts. But
since directory listing would be denied, the session gc won't be able  to do
his job anymore (look at ps_files_cleanup_dir() in mod_files.c).

A quick workaround (another one!) would be a simple cron script running as
root to do the gc.

Any other (better) way?

Regards,
Christophe Sollet.








Thread (20 messages)

« previous php.dev (#78898) next »