Auth module security flaw?
| From: | Marius Andreiana | Date: | Mon, 28 Jan 2002 17:45:20 +0000 |
| Subject: | Auth module security flaw? | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-4248@lists.php.net to get a copy of this message | ||
Hi, I have a question about Auth module.
I see it registers the session variable "auth", but I don't know how
will it work in case you have several applications on the save
server (each with a different auth).
What prevents a user, once logged in in an application, to have
access to the other applications? He'll get the same session_id
unless the session_id is enforced for each application to be
something like $application_name . $random_string
Thanks
--
You don't have to go to jail for helping your neighbour
http://www.gnu.org/philosophy/
_________________________________________________________
Do You Yahoo!?
Get your free @yahoo.com address at http://mail.yahoo.com