note 61958 added to ref.crack
| From: | sheryl at gwu dot edu | Date: | Thu, 16 Feb 2006 00:03:02 +0000 |
| Subject: | note 61958 added to ref.crack | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-103820@lists.php.net to get a copy of this message | ||
Looking at the code for both ext/crack (PHP 4.4.2) and cracklib (2.8.6) itself, I noticed that
there's no way to pass a userID to cracklib. The getuid() call in fascist.c is going to get
the UID for the process running the http daemon.. That makes the Gecos checks mostly useless; and
while they may turn up, none of the "based on password entry" or "based on user
name" or "you are not in the password file" messages should be trusted.
----
Server IP: 216.194.113.175
Probable Submitter: 128.164.156.64
----
Manual Page -- http://www.php.net/manual/en/ref.crack.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+61958
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+61958&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+61958&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+61958&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+61958&report=yes&reason=useless
Delete: non-english -- http://master.php.net/manage/user-notes.php?action=delete+61958&report=yes&reason=non-english
Delete: already in docs -- http://master.php.net/manage/user-notes.php?action=delete+61958&report=yes&reason=already+in+docs
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+61958&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+61958&report=yes
Search -- http://master.php.net/manage/user-notes.php