variables always overwriting session variables?!
| From: | Andrew Elliston | Date: | Fri, 10 Nov 2000 13:35:14 +0000 |
| Subject: | variables always overwriting session variables?! | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-24653@lists.php.net to get a copy of this message | ||
I've recently begun experimenting with sessions in PHP4.3pl1 and seem to have hit a snag.
Variables included in the URL _always_ overwrite the variables stored in the session. Am I doing
something wrong? Or is there a way to protect against this?
If $login and $password are stored in a session, a url like http://www.foo.com/?login=foo&password=bar
overwrites the stored variables.
Essentially, here's the setup:
page1.php : user fills out a form with login and password, directed to $PHP_SELF where it checks the
login and password against a database. If the login and password are incorrect, user sees page1.php
again. If the information is correct, the page does the following:
session_start();
session_register("login");
session_register("password");
header("Location:page2.php");
page2.php : this page calls a function that checks the login and password registered with the
session. It compares them against the database. If the login and password are incorrect, the user is
redirected to page1.php to login. If the login and password are correct, the rest of the page is
displayed. The problem here is that if the user enters a URL like:
http://www.page2.php/?login=andrew&password=foo
They automatically overwrite the variables stored in the session. This allows them to bypass the
login system.
Granted, to bypass the system like this, they need to know the login information anyway, but this
seems fairly insecure.
Thanks,
Andrew Elliston