Re: Session Variable Security
| From: | Julie Meloni | Date: | Thu, 06 Jul 2000 00:19:37 +0000 |
| Subject: | Re: Session Variable Security | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-5114@lists.php.net to get a copy of this message | ||
Richard Lynch wrote:
>
> In article
> <Pine.SOL.3.96.1000704160659.16267A-100000@minyos.its.rmit.edu.au>,
> s9913089@minyos.its.rmit.edu.au (Morty McFly) wrote:
>
> > I read somewhere that you cannot directly change the value of a registered
> > session variable using POST or GET- for *very important security reasons*.
> > And that these must be explicitly reassigned values.
> >
> > Could anyone elaborate as to what these *very important security reasons*
> > might be?
>
> Wild Guess:
>
> These values are being written into /tmp files on your server.
> Thus, a hacker could somehow set the data in their session file to some
> executable code, and then somehow execute it...
>
> Granted, this would not be trivial to do, but the folks who worry about
> security tend to worry about what *can* be done, not what's easy to do.
Well, the original statement in question sounds an awful lot like
something I tend to say while wildly overgeneralizing something, so I'll
just elaborate on what I meant. Again, in a very broad, sweeping
manner....
Say you have a really unimaginative brain, and your registered session
variables for your super-top-secret corporate/financial/stock
market/whatever web site are like "valid_user" and "my_account_number"
and so on. Or, you've created a shopping system and put all of your
product info into sessions (i'd use a db, but hey...) like "item_cost".
Then say you have a rogue/smart/bored user who likes to try to sit and
guess things like that. If you could re-write the registered session
variable using GET or POST, then you type:
http://www.yoursecretdomain.com/joesaccountinfo/menu.phtml?valid_user=1
and if valid_user is a registered session variable, '1' would be its new
value, and if you're not joe and shouldn't be in /joesaccountinfo/, then
that'd be bad.
Or http://www.yourshop.com/i_wanna_buy.phtml?item=555&item_cost=10.00
and item_cost should _really_ be 1000.00....you get the picture.
Sure, it requires you know the names of variables ahead of time, but
people crack _passwords_ all the time without knowledge ahead of time,
why not sit and guess variable names? And of course, you should
validate any variables in your scripts anyway, to avoid mis-typing and
hack attempts, etc etc.
Someone who speaks technical-speak, like the session developer guys,
please feel free to give a highly technical reason. :)
- julie
+------------------------------------------------+
| Julie Meloni (jcm@i2ii.com) |
| Tech. Director, i2i Interactive (www.i2ii.com) |
| |
| "PHP Essentials" & "PHP Fast & Easy" |
| http://www.thickbook.com/ |
+------------------------------------------------+