apache & php Authentication security problem
| From: | moon | Date: | Fri, 18 Jan 2002 00:55:53 +0000 |
| Subject: | apache & php Authentication security problem | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-77641@lists.php.net to get a copy of this message | ||
I am using Basic authentication on my school site.
It works as I want, but when I use php, I can read the password form
variable $php_auth_pw / $HTTP_SERVER_VARS["PHP_AUTH_PW"].
I think it have a security problem when the student can read another one
password using php.
But I have no ideal how to protect it.
Is it the setting of apache or php?
moon
CCC Ming Kei College
kei-lc@cccmkc.edu.hk