Re: Session Variable Security
| From: | (Richard Lynch) | Date: | Wed, 05 Jul 2000 23:48:34 +0000 |
| Subject: | Re: Session Variable Security | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-5102@lists.php.net to get a copy of this message | ||
In article
<Pine.SOL.3.96.1000704160659.16267A-100000@minyos.its.rmit.edu.au>,
s9913089@minyos.its.rmit.edu.au (Morty McFly) wrote:
> I read somewhere that you cannot directly change the value of a registered
> session variable using POST or GET- for *very important security reasons*.
> And that these must be explicitly reassigned values.
>
> Could anyone elaborate as to what these *very important security reasons*
> might be?
Wild Guess:
These values are being written into /tmp files on your server.
Thus, a hacker could somehow set the data in their session file to some
executable code, and then somehow execute it...
Granted, this would not be trivial to do, but the folks who worry about
security tend to worry about what *can* be done, not what's easy to do.
I dunno what OSes have for default settings on /tmp files and/or their
executability though. Sure doesn't seem like a Good Idea (tm) to have
/tmp files be executable, but I'm no expert.
--
Richard Lynch | If this was worth $$$ to you, buy a CD
US Customer Support Director | from one of the artists listed here:
Zend Technologies USA | http://www.L-I-E.com/artists.htm
http://www.zend.com | (this has nothing to do with Zend,
duh!)