Bug #18391: Plaintext password revelation using KerberosV5 authentication
| From: | paul at myitcv dot org dot uk | Date: | Wed, 17 Jul 2002 12:39:27 +0000 |
| Subject: | Bug #18391: Plaintext password revelation using KerberosV5 authentication | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-14403@lists.php.net to get a copy of this message | ||
From: paul@myitcv.org.uk
Operating system: Linux 2.2.16-3 (Redhat 6.2)
PHP version: 4.2.1
PHP Bug Type: HTTP related
Bug description: Plaintext password revelation using KerberosV5 authentication
.htaccess file as follows:
---8<---
SSLRequireSSL
AuthType KerberosV5
AuthName Blah
require valid-user
---8<---
Configure line as follows:
---8<---
'./configure' '--with-apache=../apache'
'--with-config-file-path=/usr/local/apache/conf' '--with-pgsql=/usr'
'--with-xml' '--enable-safe-mode' '--enable-memory-limit'
'--with-gd'
'--without-mysql' '--with-imap=/usr' '--with-imap-ssl'
'--with-kerberos'
'--enable-versioning' '--with-jpeg-dir=/usr'
'--with-xpm-dir=/usr/X11R6'
'--with-curl'
---8<---
Via PHP_AUTH_PW and PHP_AUTH_USER in the _SERVER var, users password is
made available when AuthType is as above. According to the following quote
from the page http://www.php.net/manual/en/features.http-auth.php:
---8<---
In order to prevent someone from writing a script which reveals the
password for a page that was authenticated through a traditional external
mechanism, the PHP_AUTH variables will not be set if external
authentication is enabled for that particular page. In this case,
REMOTE_USER can be used to identify the externally-authenticated user. So,
$_SERVER['REMOTE_USER'].
---8<---
this should not be possible. Is KerberosV5 not an external authentication
mechanism? On a shared system this behaviour is potentially disastrous as
a malicious user could easily coax users to a secure, password protected
page and snoop their _plain text_ passwords.
Any thoughts?
Paul J
--
Edit bug report at http://bugs.php.net/?id=18391&edit=1
--
Fixed in CVS: http://bugs.php.net/fix.php?id=18391&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=18391&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=18391&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=18391&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=18391&r=support
Expected behavior: http://bugs.php.net/fix.php?id=18391&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=18391&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=18391&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=18391&r=globals