note 21770 added to ref.session
| From: | session_id at my_site_got_hacked dot com | Date: | Sun, 26 May 2002 04:50:35 +0000 |
| Subject: | note 21770 added to ref.session | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-31042@lists.php.net to get a copy of this message | ||
REGARDING:
" The <?=SID?> is not necessary, if --enable-trans-sid was used to compile PHP.
Huomaa: Non-relative URLs are assumed to point to external sites and hence don't append the
SID, as it would be a security risk to leak the SID to a different server."
This is a crock of shit.
So its a security risk to leak the SID?
Then how come the APACHE logs on other servers are showing up the session ID for my users? WHEN I
HAVE NO SESSION ID IN THE LINK!!!
Because the Session ID is still forwarded in the REFERRER!!!!!
This is HUGE SECURITY HOLE and there is no excuse that this has been known and is not thrown in
peoples face on this page.
Sincerely,
Mr. My Site Got Hacked.
READ THIS:
http://www.webkreator.com/cms/view.php/1665.html
The HTTP_REFERER problem
If your site uses the wonderful URL rewriting feature then you have one more thing to worry about.
Every click to an external site will reveal the session id to it. It is not that the problem is in
the PHP code, the URL rewriting code does not append session ids to absolute URLs. But, the browser
will send the URL of the page to the external site in the HTTP_REFERER header.
Solving this problem requires some discipline. Instead of sending people to external sites directly,
send them through a simple script. You also need to reference this script through an absolute URL to
a
http://www.webkreator.com/redirect.php?http://www.google.com
My first version of the script looked like this:
<? header('Location: ' . $HTTP_SERVER_VARS['QUERY_STRING']) ?>
But I found out that Netscape uses the URI of the original page (the one containing the SID) when
you use redirection. Oh well, another way is to use the META refresh technique:
<meta http-equiv="refresh" content="0; url=<? echo
$HTTP_SERVER_VARS['QUERY_STRING']?>">
Be warned that this will completely hide the referrer information. If you want other sites to know
that you are sending people their way, use the Javascript redirection technique instead. "
--
http://www.php.net/manual/en/ref.session.php
http://master.php.net/manage/user-notes.php?action=edit+21770
http://master.php.net/manage/user-notes.php?action=delete+21770
http://master.php.net/manage/user-notes.php?action=reject+21770