Re: apache & php Authentication security problem

From: Date: Mon, 21 Jan 2002 12:01:22 +0000
Subject: Re: apache & php Authentication security problem
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-77658@lists.php.net to get a copy of this message
Hi, > I am using Basic authentication on my school site. > It works as I want, but when I use php, I can read the password form > variable $php_auth_pw / $HTTP_SERVER_VARS["PHP_AUTH_PW"]. > I think it have a security problem when the student can read another one > password using php. > But I have no ideal how to protect it. > Is it the setting of apache or php? why should this be a security problem? you can only read out your OWN user/password and not from others. And I think YOU already know YOUR own password, therefore it's not a secret. besides, you have to be able to run a php script within a protected area. Kind Regards, Daniel Lorch -- @echo "Hello, World";

« previous php.dev (#77658) next »