Re: Unofficial PEAR meeting summary
| From: | Daniel Convissor | Date: | Thu, 06 May 2004 23:36:09 +0000 |
| Subject: | Re: Unofficial PEAR meeting summary | ||
| References: | 1 2 3 4 5 6 7 8 9 10 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-28917@lists.php.net to get a copy of this message | ||
On Thu, May 06, 2004 at 03:39:43PM -0500, Paul M Jones wrote:
> On May 6, 2004, at 3:34 PM, Cipriano Groenendal wrote:
>
> >However, we are not passing anything in the open, except for perhaps
> >and
> >md5sum of the password. This could be considered
secure by
> >most
> >people ,
> >unless you're really paranoid :)
It is not secure at all. When I first joined up, I was surprised to see
that's the authentication method.
> It leaves open the possibility of a brute force
> dictionary attack,
A dictionary attack isn't necessary. All a nepharious person needs to do
is forge a cookie named PHP_USER and put the persons user name in and then
forge another cookie named PEAR_PW and put the md5sum in it.
Let alone, someone could snoop hits to login.php and grab the actual
password.
--Dan
--
T H E A N A L Y S I S A N D S O L U T I O N S C O M P A N Y
data intensive web and database programming
http://www.AnalysisAndSolutions.com/
4015 7th Ave #4, Brooklyn NY 11232 v: 718-854-0335 f: 718-854-0409