RE: [PHP-DEV] [PROPOSAL] defense against session takeovers

From: Date: Fri, 01 Feb 2002 18:27:35 +0000
Subject: RE: [PHP-DEV] [PROPOSAL] defense against session takeovers
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-4337@lists.php.net to get a copy of this message
Well theoretically proxies should always send the original IP along in the header. Unfortunately some proxies are not good about this (or a proxy queries a proxy whatever). But under certain circumstances you may want this feature nonetheless (security is soo much more important to you than pleasing everybody in which case you can actually tell your userbase to go use a different ISP) Best regards, Lukas Smith smith@dybnet.de _______________________________ DybNet Internet Solutions GbR Alt Moabit 89 10559 Berlin Germany Tel. : +49 30 83 22 50 00 Fax : +49 30 83 22 50 07 www.dybnet.de info@dybnet.de _______________________________ > -----Original Message----- > From: George Schlossnagle [mailto:george@omniti.com] > Sent: Friday, February 01, 2002 7:15 PM > To: Rasmus Lerdorf > Cc: Sander Roobol; php-dev@lists.php.net > Subject: Re: [PHP-DEV] [PROPOSAL] defense against session takeovers > > Also, ISPs (like AOL) who use farms of proxy caches will change a users > apparent ip during a single session. (i.e. concurrent requests may come > from different ips). > > George > > On Friday, February 1, 2002, at 11:58 AM, Rasmus Lerdorf wrote: > > > Bringing the user's ip into the mix is going to cause all sorts of hard > > to > > track down problems as many many people do not have static ips. > > Having a > > session break because their lease expires and they are assigned a new > > one > > will confuse everyone. > > > > As far as I am concerned this is a documentation issue. > > > > -Rasmus > > > > On Fri, 1 Feb 2002, Sander Roobol wrote: > > > >> [PROBLEM] > >> Sessions can easily be taken over by other, malicious users. All you > >> need is the session-id and you're done. > >> User who have read-access to the directory where PHP stores it's > >> session-data, can read the ids directly from the filenames. I don't > >> think many administrators are aware of the security risks involved in > >> storing sessions in world-readable directories (like /tmp, which is the > >> default by now). > >> > >> As you'll understand, the possibility of taking over sessions, and that > >> way claiming to be somebody else, can be a serious security hazard. > >> There is a workaround, but IMO, PHP should be as secure as possible > >> without a tricky configuration. > >> > >> Note: this problem is only valid for filebased sessions. > >> > >> [WORKAROUND] > >> A workaround is to create a directory which is only readable by the > >> user who runs the webserver. > >> > >> [PROPOSAL] > >> Instead of directly using the session-id, an alternate id which depends > >> on the session-id and possibly some client-specific data should be used > >> to construct a filename to store the session data. > >> A good option would be, IMO, creating a MD5 hash of the session-id and > >> some client-specific data, like his IP address. That MD5 hash will be > >> the alternate id used to construct the filename to store the session > >> data. > >> > >> [ADVANTAGES] > >> No tricky configuration necessary to assure a safe session-setup. > >> > >> [DISADVANTAGES] > >> There's a slight overhead involved in creating the hash to construct > >> the filename with the session data for each request. > >> > >> > >> Unfortunately my C skills and my knowlegde of PHP internals are by far > >> not supporting to implement this. > >> However, I would like hear any reactions on this proposal. > >> > >> Sander > >> > >> -- > >> PHP Development Mailing List > >> <http://www.php.net/> > >> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net > >> For additional commands, e-mail: php-dev-help@lists.php.net > >> To contact the list administrators, e-mail: php-list- > >> admin@lists.php.net > >> > > > > > > -- > > PHP Development Mailing List <http://www.php.net/> > > To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net > > For additional commands, e-mail: php-dev-help@lists.php.net > > To contact the list administrators, e-mail: php-list-admin@lists.php.net > > > > > > > > // George Schlossnagle > // Director of Operations > // Community Connect, Inc. > // 1024D/1100A5A0  1370 F70A 9365 96C9 2F5E  56C2 B2B9 262F 1100 A5A0 > > > > -- > PHP Development Mailing List <http://www.php.net/> > To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net > For additional commands, e-mail: php-dev-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.pear.dev (#4337) next »