Re: Re: cvs: php4 /ext/session php_session.h session.c
| From: | Sascha Schumann | Date: | Wed, 12 Jun 2002 22:37:30 +0000 |
| Subject: | Re: Re: cvs: php4 /ext/session php_session.h session.c | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-85182@lists.php.net to get a copy of this message | ||
> I noticed this risk long time before and I think it's a kind of
> security fix as Sascha's comment, isn't it?
That depends on your viewpoint.
From my perspective, this is not urgent. It is not like an
attacker can gain access to the server, it just makes it a
bit harder for attackers to exploit ignorant people. That
group will always be vulnerable to social engineering,
something which can only be addressed by education.
Technology is not able to upgrade your brain, after all.
- Sascha