note 28557 added to ref.session

From: Date: Thu, 16 Jan 2003 19:13:38 +0000
Subject: note 28557 added to ref.session
Groups: php.notes 
Request: Send a blank email to php-notes+get-42236@lists.php.net to get a copy of this message
There are a few comments above about how using sessions might not be secure, but quite apart from session hijacking, there is a mistake that I think a lot of people are making at the moment that everyone needs to stop and make sure they aren't one. This mistake arises from having the 'register_globals' setting on. Take the following example code which is meant to maintain a session variable for whether a user is logged in and allow them to log in using a username and password if they aren't logged in, or give an option for logging out if they are: <?php session_register ("logged_in"); if (!strcmp($user, "user") && !strcmp($pass, "password")) $logged_in = 1; if ($logout) $logged_in = 0; if ($logged_in) echo "logged in. <A href=\"sestest.php?logout=1\">log out</A>"; else echo "<FORM action=sestest.php method=get>User: <INPUT type=text name=user><BR>Password: <INPUT type=text name=pass><BR><INPUT type=submit></FORM>"; ?> This works fine under normal use, but an attacker can log in without knowing the username or password by accessing '.../sestest.php?logged_in=1', which will set the session variable 'logged_in' to the value 1. However, once a session variable has been set, it cannot be overridden in this fashion, so one solution is to use code like the code shown above (which has no explanation attached as to why you should do it that way) that uses session_is_registered: <?php session_start (); if (!session_is_registered ("logged_in")) { $logged_in = 0; session_register ("logged_in"); } ... ?> -- http://www.php.net/manual/en/ref.session.php http://master.php.net/manage/user-notes.php?action=edit+28557 http://master.php.net/manage/user-notes.php?action=delete+28557 http://master.php.net/manage/user-notes.php?action=reject+28557

« previous php.notes (#42236) next »