Oops.

Published March 09, 2005
Advertisement
Here's a PHP snafu for you to avoid. A friend of mine made a site for someone and used PHP for the job. I decided to check the site out today and what did I discover? A security hole! Oh noes. It was really no fault of my friend, just oversight.

REGISTER_GLOBALS was apparently turned on and he used session IDs. In various places on the site he was getting user Ids and whatnot for the current session.

If you had an account and were signed in and knew a user ID, you could go their profile and it would set the current session to their profile ID, when you went to "My Account" you had access to all of the OTHER persons info. This included the ability to change passwords and e-mail and whatnot. Not cool. Luckily the site has only been live for a day so it's doubtful anyone else has discovered it. The server he had to use was a shared server, so he couldn't really change the settings, but he had a workaround by changing the variable names.
0 likes 1 comments

Comments

Rob Loach
You have to be careful with that one.
March 09, 2005 03:17 PM
You must log in to join the conversation.
Don't have a GameDev.net account? Sign up!
Advertisement

Latest Entries

Update++

1209 views

Untitled

926 views

Hooray!

1003 views

Untitled

1002 views

Updates

1020 views

Cheapness!

952 views

Oh dear.

950 views

My first Perl!

1067 views

Oh the Oxycodone!

1025 views
Advertisement