Re: Session Variable Security
| From: | Szii | Date: | Fri, 07 Jul 2000 17:23:58 +0000 |
| Subject: | Re: Session Variable Security | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-5413@lists.php.net to get a copy of this message | ||
The session are in your /tmp file. Those session files are owned, under Un*x,
usually as the "nobody" account. If you could modify those files directly,
you
could execute your own code, make system calls, modify OTHER sessions
(since they're owned by the same virtual "nobody" account) and cause other
problems...including overwriting parts of the site if the permissions
aren't locked
down. Under a Windows machine, you can do the same, but it's more open
once that point is breached since they have less user security and usually
the webserver's run as a Service (beaucoup permissions.)
-Szii
At 06:48 PM 7/5/00 -0500, Richard Lynch wrote:
>In article
><Pine.SOL.3.96.1000704160659.16267A-100000@minyos.its.rmit.edu.au>,
>s9913089@minyos.its.rmit.edu.au (Morty McFly) wrote:
>
>> I read somewhere that you cannot directly change the value of a registered
>> session variable using POST or GET- for *very important security reasons*.
>> And that these must be explicitly reassigned values.
>>
>> Could anyone elaborate as to what these *very important security reasons*
>> might be?
>
>Wild Guess:
>
>These values are being written into /tmp files on your server.
>Thus, a hacker could somehow set the data in their session file to some
>executable code, and then somehow execute it...
>
>Granted, this would not be trivial to do, but the folks who worry about
>security tend to worry about what *can* be done, not what's easy to do.
>
>I dunno what OSes have for default settings on /tmp files and/or their
>executability though. Sure doesn't seem like a Good Idea (tm) to have
>/tmp files be executable, but I'm no expert.
>--
>Richard Lynch | If this was worth $$$ to you, buy a CD
>US Customer Support Director | from one of the artists listed here:
>Zend Technologies USA | http://www.L-I-E.com/artists.htm
>http://www.zend.com | (this has nothing to do with
>Zend, duh!)
>
>--
>PHP General Mailing List (http://www.php.net/)
>To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
>For additional commands, e-mail: php-general-help@lists.php.net
>To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>
>