Re: Session Variable Security

From: Date: Thu, 06 Jul 2000 00:19:37 +0000
Subject: Re: Session Variable Security
References: 1 2 3  Groups: php.general 
Request: Send a blank email to php-general+get-5114@lists.php.net to get a copy of this message
Richard Lynch wrote: > > In article > <Pine.SOL.3.96.1000704160659.16267A-100000@minyos.its.rmit.edu.au>, > s9913089@minyos.its.rmit.edu.au (Morty McFly) wrote: > > > I read somewhere that you cannot directly change the value of a registered > > session variable using POST or GET- for *very important security reasons*. > > And that these must be explicitly reassigned values. > > > > Could anyone elaborate as to what these *very important security reasons* > > might be? > > Wild Guess: > > These values are being written into /tmp files on your server. > Thus, a hacker could somehow set the data in their session file to some > executable code, and then somehow execute it... > > Granted, this would not be trivial to do, but the folks who worry about > security tend to worry about what *can* be done, not what's easy to do. Well, the original statement in question sounds an awful lot like something I tend to say while wildly overgeneralizing something, so I'll just elaborate on what I meant. Again, in a very broad, sweeping manner.... Say you have a really unimaginative brain, and your registered session variables for your super-top-secret corporate/financial/stock market/whatever web site are like "valid_user" and "my_account_number" and so on. Or, you've created a shopping system and put all of your product info into sessions (i'd use a db, but hey...) like "item_cost". Then say you have a rogue/smart/bored user who likes to try to sit and guess things like that. If you could re-write the registered session variable using GET or POST, then you type: http://www.yoursecretdomain.com/joesaccountinfo/menu.phtml?valid_user=1 and if valid_user is a registered session variable, '1' would be its new value, and if you're not joe and shouldn't be in /joesaccountinfo/, then that'd be bad. Or http://www.yourshop.com/i_wanna_buy.phtml?item=555&item_cost=10.00 and item_cost should _really_ be 1000.00....you get the picture. Sure, it requires you know the names of variables ahead of time, but people crack _passwords_ all the time without knowledge ahead of time, why not sit and guess variable names? And of course, you should validate any variables in your scripts anyway, to avoid mis-typing and hack attempts, etc etc. Someone who speaks technical-speak, like the session developer guys, please feel free to give a highly technical reason. :) - julie +------------------------------------------------+ | Julie Meloni (jcm@i2ii.com) | | Tech. Director, i2i Interactive (www.i2ii.com) | | | | "PHP Essentials" & "PHP Fast & Easy" | | http://www.thickbook.com/ | +------------------------------------------------+

« previous php.general (#5114) next »