Bug #18391 Updated: Plaintext password revelation using KerberosV5 authentication

From: Date: Wed, 17 Jul 2002 15:27:28 +0000
Subject: Bug #18391 Updated: Plaintext password revelation using KerberosV5 authentication
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-14414@lists.php.net to get a copy of this message
 ID:               18391
 Updated by:       sniper@php.net
 Reported By:      paul@myitcv.org.uk
-Status:           Open
+Status:           Closed
 Bug Type:         HTTP related
 Operating System: Linux 2.2.16-3 (Redhat 6.2)
 PHP Version:      4.2.1
 New Comment:

This bug has been fixed in CVS. You can grab a snapshot of the
CVS version at http://snaps.php.net/. In case this was a
documentation 
problem, the fix will show up soon at http://www.php.net/manual/.
In case this was a PHP.net website problem, the change will show
up on the PHP.net site and on the mirror sites.
Thank you for the report, and for helping us make PHP better.




Previous Comments:
------------------------------------------------------------------------

[2002-07-17 08:39:26] paul@myitcv.org.uk

.htaccess file as follows:

---8<---

SSLRequireSSL
AuthType KerberosV5
AuthName Blah
require valid-user

---8<---

Configure line as follows:

---8<---

 './configure' '--with-apache=../apache'
'--with-config-file-path=/usr/local/apache/conf' '--with-pgsql=/usr'
'--with-xml' '--enable-safe-mode' '--enable-memory-limit'
'--with-gd'
'--without-mysql' '--with-imap=/usr' '--with-imap-ssl'
'--with-kerberos' '--enable-versioning' '--with-jpeg-dir=/usr'
'--with-xpm-dir=/usr/X11R6' '--with-curl'

---8<---

Via PHP_AUTH_PW and PHP_AUTH_USER in the _SERVER var, users password is
made available when AuthType is as above. According to the following
quote from the page
http://www.php.net/manual/en/features.http-auth.php:

---8<---

 In order to prevent someone from writing a script which reveals the
password for a page that was authenticated through a traditional
external mechanism, the PHP_AUTH variables will not be set if external
authentication is enabled for that particular page. In this case,
REMOTE_USER can be used to identify the externally-authenticated user.
So, $_SERVER['REMOTE_USER']. 

---8<---

this should not be possible. Is KerberosV5 not an external
authentication mechanism? On a shared system this behaviour is
potentially disastrous as a malicious user could easily coax users to a
secure, password protected page and snoop their _plain text_
passwords.

Any thoughts?


Paul J

------------------------------------------------------------------------


-- 
Edit this bug report at http://bugs.php.net/?id=18391&edit=1



Thread (6 messages)

« previous php.bugs (#14414) next »