Re: Re: cvs: php4 /ext/session php_session.h session.c
| From: | Yasuo Ohgaki | Date: | Wed, 12 Jun 2002 22:46:01 +0000 |
| Subject: | Re: Re: cvs: php4 /ext/session php_session.h session.c | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-85183@lists.php.net to get a copy of this message | ||
Sascha Schumann wrote:
I agree. (That's the reason why I didn't mention the risk, too.)I noticed this risk long time before and I think it's a kind of security fix as Sascha's comment, isn't it?That depends on your viewpoint.From my perspective, this is not urgent. It is not like an
attacker can gain access to the server, it just makes it a
bit harder for attackers to exploit ignorant people. That
group will always be vulnerable to social engineering,
something which can only be addressed by education.
Technology is not able to upgrade your brain, after all.
I just thought it's good one for merging. I'm not strong +1, anyway.
It's also good for 4.3.0.
--
Yasuo Ohgaki