note 124290 added to function.ldap-start-tls
| From: | NOYB at NOYB dot info | Date: | Sat, 12 Oct 2019 05:34:29 +0000 |
| Subject: | note 124290 added to function.ldap-start-tls | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-212579@lists.php.net to get a copy of this message | ||
Security Warning:
To avoid the StripTLS attack vulnerability of StartTLS, code your application to not continue unless
the connection is successfully upgraded to TLS.
For StripTLS attack vulnerability anatomy details please conduct a web search for
"StripTLS".
There is a good article on Wikipedia titled "Opportunistic TLS". The "Weaknesses and
mitigations" section details the StripTLS attack vulnerability.
----
Server IP: 208.43.231.9
Probable Submitter: 82.199.157.54 (proxied: 50.53.166.123)
----
Manual Page -- http://php.net/manual/en/function.ldap-start-tls.php
Edit -- https://master.php.net/note/edit/124290
Del: integrated -- https://master.php.net/note/delete/124290/integrated
Del: useless -- https://master.php.net/note/delete/124290/useless
Del: bad code -- https://master.php.net/note/delete/124290/bad+code
Del: spam -- https://master.php.net/note/delete/124290/spam
Del: non-english -- https://master.php.net/note/delete/124290/non-english
Del: in docs -- https://master.php.net/note/delete/124290/in+docs
Del: other reasons-- https://master.php.net/note/delete/124290
Reject -- https://master.php.net/note/reject/124290
Search -- https://master.php.net/manage/user-notes.php