Re: Session Variable Security

From: Date: Wed, 05 Jul 2000 23:48:34 +0000
Subject: Re: Session Variable Security
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-5102@lists.php.net to get a copy of this message
In article <Pine.SOL.3.96.1000704160659.16267A-100000@minyos.its.rmit.edu.au>, s9913089@minyos.its.rmit.edu.au (Morty McFly) wrote: > I read somewhere that you cannot directly change the value of a registered > session variable using POST or GET- for *very important security reasons*. > And that these must be explicitly reassigned values. > > Could anyone elaborate as to what these *very important security reasons* > might be? Wild Guess: These values are being written into /tmp files on your server. Thus, a hacker could somehow set the data in their session file to some executable code, and then somehow execute it... Granted, this would not be trivial to do, but the folks who worry about security tend to worry about what *can* be done, not what's easy to do. I dunno what OSes have for default settings on /tmp files and/or their executability though. Sure doesn't seem like a Good Idea (tm) to have /tmp files be executable, but I'm no expert. -- Richard Lynch | If this was worth $$$ to you, buy a CD US Customer Support Director | from one of the artists listed here: Zend Technologies USA | http://www.L-I-E.com/artists.htm http://www.zend.com | (this has nothing to do with Zend, duh!)

« previous php.general (#5102) next »