#19251 [NEW]: Passwords exposed when using external authentification

From: Date: Thu, 05 Sep 2002 15:08:19 +0000
Subject: #19251 [NEW]: Passwords exposed when using external authentification
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-18492@lists.php.net to get a copy of this message
From: james.mcininch@attbi.com Operating system: Solaris and Linux PHP version: 4.2.2 PHP Bug Type: Apache related Bug description: Passwords exposed when using external authentification This bug is a security issue first reported for 4.0.4 as bug #9022 and has yet to be fixed. The security flaw remains. According to the PHP documentation, if a user is authenticated using and external HTTP basic authentification mechanism such as the various mechanisms available under Apache (I tested file-based and LDAP-based authentification), the PHP_AUTH_PW and PHP_AUTH_USER variables SHOULD NOT BE SET. This is the correct and desired behavior as it prevents malicious users from capturing this information in environments where they are permitted to host PHP scripts that authenticate off an external resource. However, the password information is always returned by PHP - exposing the user password. Demonstrating the exploit is very simple: Make a directory with the following script in it: <?php phpinfo(); ?> Then create an .htaccess file like: AuthType Basic AuthName "This is a test" AuthUserfile .htpasswd Require valid-user ... and make the .htpasswd file with a username and password. When you go to the phpinfo page, note that the username and password are contained on the page (as PHP_AUTH_USER and PHP_AUTH_PW respectively). -- Edit bug report at http://bugs.php.net/?id=19251&edit=1 -- Try a CVS snapshot: http://bugs.php.net/fix.php?id=19251&r=trysnapshot Fixed in CVS: http://bugs.php.net/fix.php?id=19251&r=fixedcvs Fixed in release: http://bugs.php.net/fix.php?id=19251&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=19251&r=needtrace Try newer version: http://bugs.php.net/fix.php?id=19251&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=19251&r=support Expected behavior: http://bugs.php.net/fix.php?id=19251&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=19251&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=19251&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=19251&r=globals

« previous php.bugs (#18492) next »