Re: Unofficial PEAR meeting summary
| From: | Paul M Jones | Date: | Thu, 06 May 2004 20:39:43 +0000 |
| Subject: | Re: Unofficial PEAR meeting summary | ||
| References: | 1 2 3 4 5 6 7 8 9 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-28909@lists.php.net to get a copy of this message | ||
On May 6, 2004, at 3:34 PM, Cipriano Groenendal wrote:
If you look at Auth/Container/PEAR.php, you'll see that the Auth package
uses an RPC call to get userinfo. Within taht is the md5sum of the pass,
which is compared to a locally md5'd password string. Wether this is by
design, or a bug, in cases like this it's quite cool :)
However, we are not passing anything in the open, except for perhaps and
md5sum of the password. This could be considered secure by most people ,
unless you're really paranoid :)
Which I am. :-) It leaves open the possibility of a brute force dictionary attack, and while it might take a while, I bet your password is not that strong. Better to encrypt the connection via https, in my opinion; that way, the password hash never goes into the clear, and interlopers cannot harvest the hashes for dictionary attacks.
--
Paul M. Jones
Savant: the simple alternative to Smarty for PHP.
http://phpsavant.com/
DB_Table: build RDBMS tables and XHTML forms in one PHP class.
http://wiki.ciaweb.net/yawiki/index.php?area=DB_Table
Yawiki: a collaborative online documentation system.
http://wiki.ciaweb.net/yawiki/index.php?area=Yawiki