Re: Session Variable Security

From: Date: Fri, 07 Jul 2000 17:23:58 +0000
Subject: Re: Session Variable Security
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-5413@lists.php.net to get a copy of this message
The session are in your /tmp file. Those session files are owned, under Un*x, usually as the "nobody" account. If you could modify those files directly, you could execute your own code, make system calls, modify OTHER sessions (since they're owned by the same virtual "nobody" account) and cause other problems...including overwriting parts of the site if the permissions aren't locked down. Under a Windows machine, you can do the same, but it's more open once that point is breached since they have less user security and usually the webserver's run as a Service (beaucoup permissions.) -Szii At 06:48 PM 7/5/00 -0500, Richard Lynch wrote: >In article ><Pine.SOL.3.96.1000704160659.16267A-100000@minyos.its.rmit.edu.au>, >s9913089@minyos.its.rmit.edu.au (Morty McFly) wrote: > >> I read somewhere that you cannot directly change the value of a registered >> session variable using POST or GET- for *very important security reasons*. >> And that these must be explicitly reassigned values. >> >> Could anyone elaborate as to what these *very important security reasons* >> might be? > >Wild Guess: > >These values are being written into /tmp files on your server. >Thus, a hacker could somehow set the data in their session file to some >executable code, and then somehow execute it... > >Granted, this would not be trivial to do, but the folks who worry about >security tend to worry about what *can* be done, not what's easy to do. > >I dunno what OSes have for default settings on /tmp files and/or their >executability though. Sure doesn't seem like a Good Idea (tm) to have >/tmp files be executable, but I'm no expert. >-- >Richard Lynch | If this was worth $$$ to you, buy a CD >US Customer Support Director | from one of the artists listed here: >Zend Technologies USA | http://www.L-I-E.com/artists.htm >http://www.zend.com | (this has nothing to do with >Zend, duh!) > >-- >PHP General Mailing List (http://www.php.net/) >To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net >For additional commands, e-mail: php-general-help@lists.php.net >To contact the list administrators, e-mail: php-list-admin@lists.php.net > > >

« previous php.general (#5413) next »