sessions and securety
| From: | Boris Erdmann | Date: | Thu, 22 Jul 1999 05:52:11 +0000 |
| Subject: | sessions and securety | ||
| Groups: | php.version4 | ||
| Request: | Send a blank email to php-version4+get-2490@lists.php.net to get a copy of this message | ||
As of now all session data is stored in one directory -
thus allowing access to that data from all virtual servers
(if php4 is compiled as mod_php).
Now an ISP's clients can spy their clients' personal data if once stored
as session variable.
A bad situation - i think.
the server name should be part of the session store path and fopen (e.a.)
should be validated against the session store path.
Boris