Bug #18391: Plaintext password revelation using KerberosV5 authentication

From: Date: Wed, 17 Jul 2002 12:39:27 +0000
Subject: Bug #18391: Plaintext password revelation using KerberosV5 authentication
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-14403@lists.php.net to get a copy of this message
From: paul@myitcv.org.uk Operating system: Linux 2.2.16-3 (Redhat 6.2) PHP version: 4.2.1 PHP Bug Type: HTTP related Bug description: Plaintext password revelation using KerberosV5 authentication .htaccess file as follows: ---8<--- SSLRequireSSL AuthType KerberosV5 AuthName Blah require valid-user ---8<--- Configure line as follows: ---8<--- './configure' '--with-apache=../apache' '--with-config-file-path=/usr/local/apache/conf' '--with-pgsql=/usr' '--with-xml' '--enable-safe-mode' '--enable-memory-limit' '--with-gd' '--without-mysql' '--with-imap=/usr' '--with-imap-ssl' '--with-kerberos' '--enable-versioning' '--with-jpeg-dir=/usr' '--with-xpm-dir=/usr/X11R6' '--with-curl' ---8<--- Via PHP_AUTH_PW and PHP_AUTH_USER in the _SERVER var, users password is made available when AuthType is as above. According to the following quote from the page http://www.php.net/manual/en/features.http-auth.php: ---8<--- In order to prevent someone from writing a script which reveals the password for a page that was authenticated through a traditional external mechanism, the PHP_AUTH variables will not be set if external authentication is enabled for that particular page. In this case, REMOTE_USER can be used to identify the externally-authenticated user. So, $_SERVER['REMOTE_USER']. ---8<--- this should not be possible. Is KerberosV5 not an external authentication mechanism? On a shared system this behaviour is potentially disastrous as a malicious user could easily coax users to a secure, password protected page and snoop their _plain text_ passwords. Any thoughts? Paul J -- Edit bug report at http://bugs.php.net/?id=18391&edit=1 -- Fixed in CVS: http://bugs.php.net/fix.php?id=18391&r=fixedcvs Fixed in release: http://bugs.php.net/fix.php?id=18391&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=18391&r=needtrace Try newer version: http://bugs.php.net/fix.php?id=18391&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=18391&r=support Expected behavior: http://bugs.php.net/fix.php?id=18391&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=18391&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=18391&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=18391&r=globals

« previous php.bugs (#14403) next »