News Feed
Sections




News Archive
Looking for more information on how to do PHP the right way? Check out PHP: The Right Way

Stefan Esser's Blog:
What site do you want to break today?
June 18, 2007 @ 08:48:00

In a new post to the PHP Security Blog, Stefan Esser points out a recent commit to the PHP core as a fix to the session handling in PHP:

I just came back home and saw a very recent commit to PHP's session management. It is another attempt to fix the session cookie attribute injection that the PHP developers already tried to fix in PHP 5.2.3 without giving any credits. [...] their new fix that consists of blacklisting a bunch of legal characters from the session id, will most probably result in hundreds or thousands of broken sites.

Stefan points out that the fix blocks several valid characters that sites could potentially use in their session IDs, and that with this new code in place, it could drastically effect those site's functionality.

As of the time of this post, however, it seems that the issue has been recognized and corrected so as not to cause the above mentioned issue in future updates.

0 comments voice your opinion now!
session bugfix commit illegal character session bugfix commit illegal character


blog comments powered by Disqus

Similar Posts

Rob Allen's Blog: UTF8, PHP and MySQL

Zend Developer Zone: The ZendCon Sessions Episode 7: High Performance PHP & MySQL Scaling Techniques

Zend Developer Zone: The ZendCon Sessions Episode 9: QEDWiki and Zend Framework

PHPMaster.com: Amazon DynamoDB: Store PHP Sessions with Load Balancer

Paul Jones' Blog: Solar 0.27.0 and 0.27.1 Released


Community Events

Don't see your event here?
Let us know!


example api introduction framework community performance symfony2 series library extension opinion podcast conference release laravel version php7 application interview voicesoftheelephpant

All content copyright, 2015 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework