[mod_python] File Sessions security problem?

Jim Gallacher jpg at jgassociates.ca
Wed Jun 21 15:16:07 EDT 2006


marinus van aswegen wrote:
> Hi
> 
> I have been playing with mod_python (ubuntu std, breezy build) and I
> noticed that the sessions db is stored in the /tmp dir with
> permissions that will permit any user to read the file. I'm not to
> happy with this since I store some very sensitive info in the session
> object.
> 
> It's easy to chmod it, but perhaps it would be better to create the
> file with more restrictive permissions?

What version of mod_python are you using? Version 3.2.8 allows you to 
specify the the path and filename. Check the docs.

Jim



More information about the Mod_python mailing list