note 21770 added to ref.session

From: Date: Sun, 26 May 2002 04:50:35 +0000
Subject: note 21770 added to ref.session
Groups: php.notes 
Request: Send a blank email to php-notes+get-31042@lists.php.net to get a copy of this message
REGARDING: " The <?=SID?> is not necessary, if --enable-trans-sid was used to compile PHP. Huomaa: Non-relative URLs are assumed to point to external sites and hence don't append the SID, as it would be a security risk to leak the SID to a different server." This is a crock of shit. So its a security risk to leak the SID? Then how come the APACHE logs on other servers are showing up the session ID for my users? WHEN I HAVE NO SESSION ID IN THE LINK!!! Because the Session ID is still forwarded in the REFERRER!!!!! This is HUGE SECURITY HOLE and there is no excuse that this has been known and is not thrown in peoples face on this page. Sincerely, Mr. My Site Got Hacked. READ THIS: http://www.webkreator.com/cms/view.php/1665.html The HTTP_REFERER problem If your site uses the wonderful URL rewriting feature then you have one more thing to worry about. Every click to an external site will reveal the session id to it. It is not that the problem is in the PHP code, the URL rewriting code does not append session ids to absolute URLs. But, the browser will send the URL of the page to the external site in the HTTP_REFERER header. Solving this problem requires some discipline. Instead of sending people to external sites directly, send them through a simple script. You also need to reference this script through an absolute URL to a http://www.webkreator.com/redirect.php?http://www.google.com My first version of the script looked like this: <? header('Location: ' . $HTTP_SERVER_VARS['QUERY_STRING']) ?> But I found out that Netscape uses the URI of the original page (the one containing the SID) when you use redirection. Oh well, another way is to use the META refresh technique: <meta http-equiv="refresh" content="0; url=<? echo $HTTP_SERVER_VARS['QUERY_STRING']?>"> Be warned that this will completely hide the referrer information. If you want other sites to know that you are sending people their way, use the Javascript redirection technique instead. " -- http://www.php.net/manual/en/ref.session.php http://master.php.net/manage/user-notes.php?action=edit+21770 http://master.php.net/manage/user-notes.php?action=delete+21770 http://master.php.net/manage/user-notes.php?action=reject+21770

« previous php.notes (#31042) next »