Re: Sessions / logins / cookies / security
| From: | Justin French | Date: | Wed, 17 Jul 2002 10:43:37 +0000 |
| Subject: | Re: Sessions / logins / cookies / security | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-108050@lists.php.net to get a copy of this message | ||
on 17/07/02 6:51 PM, John Holmes (holmes072000@charter.net) wrote:
>> ... and I am -- A shared host server that is.
>
> Now I'm not sure on this, I haven't tested it. Has anyone?
Is this particular vulnerability only in existence when the server is pretty
open? I mean, on my particular host, I can't FTP to anything outside my
docroot, and I can't use SSH, telnet, etc.
phpinfo() says my session.save-path is /tmp -- since (in theory) I can't get
the files via telnet, FTP or HTTP, the only option I can think of would be
another user on the host gaining access to it via a PHP script... which I'm
not sure can be done, and can't really test, because I wouldn't know how to
do it.
Justin