#19251 [Opn]: Passwords exposed when using external authentification

From: Date: Thu, 05 Sep 2002 15:21:12 +0000
Subject: #19251 [Opn]: Passwords exposed when using external authentification
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-18494@lists.php.net to get a copy of this message
ID: 19251 User updated by: james.mcininch@attbi.com Reported By: james.mcininch@attbi.com Status: Open Bug Type: Apache related Operating System: Solaris and Linux PHP Version: 4.2.2 New Comment: I should add that safe_mode apparently enables the behavior mentioned in the documentation (which does not state that it is required). In fact, this is undesirable. safe_mode imposes an array of undesirable restrictions outside the passing of PHP_AUTH_*. The behavior should be as documented without the setting of safe_mode, as expected. Previous Comments: ------------------------------------------------------------------------ [2002-09-05 10:08:19] james.mcininch@attbi.com This bug is a security issue first reported for 4.0.4 as bug #9022 and has yet to be fixed. The security flaw remains. According to the PHP documentation, if a user is authenticated using and external HTTP basic authentification mechanism such as the various mechanisms available under Apache (I tested file-based and LDAP-based authentification), the PHP_AUTH_PW and PHP_AUTH_USER variables SHOULD NOT BE SET. This is the correct and desired behavior as it prevents malicious users from capturing this information in environments where they are permitted to host PHP scripts that authenticate off an external resource. However, the password information is always returned by PHP - exposing the user password. Demonstrating the exploit is very simple: Make a directory with the following script in it: <?php phpinfo(); ?> Then create an .htaccess file like: AuthType Basic AuthName "This is a test" AuthUserfile .htpasswd Require valid-user ... and make the .htpasswd file with a username and password. When you go to the phpinfo page, note that the username and password are contained on the page (as PHP_AUTH_USER and PHP_AUTH_PW respectively). ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=19251&edit=1

« previous php.bugs (#18494) next »