RE: [PHP-DEV] [PROPOSAL] defense against session takeovers
| From: | Lukas Smith | Date: | Fri, 01 Feb 2002 18:27:35 +0000 |
| Subject: | RE: [PHP-DEV] [PROPOSAL] defense against session takeovers | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-4337@lists.php.net to get a copy of this message | ||
Well theoretically proxies should always send the original IP along in
the header. Unfortunately some proxies are not good about this (or a
proxy queries a proxy whatever). But under certain circumstances you may
want this feature nonetheless (security is soo much more important to
you than pleasing everybody in which case you can actually tell your
userbase to go use a different ISP)
Best regards,
Lukas Smith
smith@dybnet.de
_______________________________
DybNet Internet Solutions GbR
Alt Moabit 89
10559 Berlin
Germany
Tel. : +49 30 83 22 50 00
Fax : +49 30 83 22 50 07
www.dybnet.de info@dybnet.de
_______________________________
> -----Original Message-----
> From: George Schlossnagle [mailto:george@omniti.com]
> Sent: Friday, February 01, 2002 7:15 PM
> To: Rasmus Lerdorf
> Cc: Sander Roobol; php-dev@lists.php.net
> Subject: Re: [PHP-DEV] [PROPOSAL] defense against session takeovers
>
> Also, ISPs (like AOL) who use farms of proxy caches will change a
users
> apparent ip during a single session. (i.e. concurrent requests may
come
> from different ips).
>
> George
>
> On Friday, February 1, 2002, at 11:58 AM, Rasmus Lerdorf wrote:
>
> > Bringing the user's ip into the mix is going to cause all sorts of
hard
> > to
> > track down problems as many many people do not have static ips.
> > Having a
> > session break because their lease expires and they are assigned a
new
> > one
> > will confuse everyone.
> >
> > As far as I am concerned this is a documentation issue.
> >
> > -Rasmus
> >
> > On Fri, 1 Feb 2002, Sander Roobol wrote:
> >
> >> [PROBLEM]
> >> Sessions can easily be taken over by other, malicious users. All
you
> >> need is the session-id and you're done.
> >> User who have read-access to the directory where PHP stores it's
> >> session-data, can read the ids directly from the filenames. I don't
> >> think many administrators are aware of the security risks involved
in
> >> storing sessions in world-readable directories (like /tmp, which is
the
> >> default by now).
> >>
> >> As you'll understand, the possibility of taking over sessions, and
that
> >> way claiming to be somebody else, can be a serious security hazard.
> >> There is a workaround, but IMO, PHP should be as secure as possible
> >> without a tricky configuration.
> >>
> >> Note: this problem is only valid for filebased sessions.
> >>
> >> [WORKAROUND]
> >> A workaround is to create a directory which is only readable by the
> >> user who runs the webserver.
> >>
> >> [PROPOSAL]
> >> Instead of directly using the session-id, an alternate id which
depends
> >> on the session-id and possibly some client-specific data should be
used
> >> to construct a filename to store the session data.
> >> A good option would be, IMO, creating a MD5 hash of the session-id
and
> >> some client-specific data, like his IP address. That MD5 hash will
be
> >> the alternate id used to construct the filename to store the
session
> >> data.
> >>
> >> [ADVANTAGES]
> >> No tricky configuration necessary to assure a safe session-setup.
> >>
> >> [DISADVANTAGES]
> >> There's a slight overhead involved in creating the hash to
construct
> >> the filename with the session data for each request.
> >>
> >>
> >> Unfortunately my C skills and my knowlegde of PHP internals are by
far
> >> not supporting to implement this.
> >> However, I would like hear any reactions on this proposal.
> >>
> >> Sander
> >>
> >> --
> >> PHP Development Mailing List
> >> <http://www.php.net/>
> >> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
> >> For additional commands, e-mail: php-dev-help@lists.php.net
> >> To contact the list administrators, e-mail: php-list-
> >> admin@lists.php.net
> >>
> >
> >
> > --
> > PHP Development Mailing List <http://www.php.net/>
> > To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
> > For additional commands, e-mail: php-dev-help@lists.php.net
> > To contact the list administrators, e-mail:
php-list-admin@lists.php.net
> >
> >
> >
>
> // George Schlossnagle
> // Director of Operations
> // Community Connect, Inc.
> // 1024D/1100A5A0 1370 F70A 9365 96C9 2F5E 56C2 B2B9 262F 1100 A5A0
>
>
>
> --
> PHP Development Mailing List <http://www.php.net/>
> To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
> For additional commands, e-mail: php-dev-help@lists.php.net
> To contact the list administrators, e-mail:
php-list-admin@lists.php.net