PHP 4.0 Bug #8827 Updated: PHP_AUTH_PW stores password when using External Authentication
| From: | csy at hjc dot edu dot sg | Date: | Sun, 29 Apr 2001 03:09:00 +0000 |
| Subject: | PHP 4.0 Bug #8827 Updated: PHP_AUTH_PW stores password when using External Authentication | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-52818@lists.php.net to get a copy of this message | ||
ID: 8827
User Update by: csy@hjc.edu.sg
Old-Status: Closed
Status: Open
Bug Type: Apache related
Description: PHP_AUTH_PW stores password when using External Authentication
Isn't this going to be a big security problem for portal sites using PHP which have a common
user base and separate groups of developers developing and selling online service?
As a malicious group of developers would be able to capture the password and assume the identity of
the user and go around "patronising" other services.
How about having a general configuration parameter that disables the storage of the password in
PHP_AUTH_PW and HTTP_RAW_HEADERS without having the need for PHP to autodetect for external
authentications?
Something like a STORE_PASSWORD = false flag in php.ini which the administrator needs to manually
set to on or off.
Thanks!
Previous Comments:
---------------------------------------------------------------------------
[2001-04-28 16:12:30] jmoore@php.net
This is the expected behaviour now.
HTTP_RAW_HEADERS holds the same information anyway.
- James
---------------------------------------------------------------------------
[2001-04-17 04:53:29] csy@hjc.edu.sg
I am currently running with safe_modes enabled but the password is still retrievable via the
PHP_AUTH_PW variable when using external authentications.
Thanks!
---------------------------------------------------------------------------
[2001-04-16 06:41:11] jmoore@php.net
This is now the expected behaviour due to various problems with being able to verify if there are
other mecanisms. If you really dont want this to happen run in safe mode or manually patch your
mod_php4.c and uncommect the line
&& auth_type(r)
this is a very buggy fix for various reasons when other mod_auth_* systems decline authentication it
will onyl work when they accept.
- James
---------------------------------------------------------------------------
[2001-01-21 01:41:08] csy@hjc.edu.sg
Under Apache-1.3.14 w/ php4.0.4pl1 and using auth_ldap for external authentication to an ldap
server, PHP_AUTH_PW stores the password of the user that authenticates successfully.
This did not occur in earlier versions of php3 and php4 and creates a problem for websites that
require external authentication before accessing and the services that are provided within the
websites are run by different parties as this will result in other parties getting hold of the
user's password.
php.ini used is similar to that which came with the php-4.0.4pl1 distribution and no settings that
are changed is related to authentication.
php is compiled using the following parameters :-
./configure
--with-apache=/usr/src/apache_1.3.14
--with-mysql=/usr
--with-dbase=yes
--enable-sysvshm=yes
--enable-sysvsem=yes
--with-config-file-path=/usr/lib
--with-system-regex=no
--enable-safe-mode=yes
--with-exec-dir=/usr/bin
--enable-track-vars=yes
--enable-magic-quotes=yes
--enable-memory-limit=yes
--with-ldap=/usr
--with-imap=/usr
--enable-ftp
--with-t1lib
--with-ndbm
--with-db
---------------------------------------------------------------------------
Full Bug description available at: http://bugs.php.net/?id=8827