Re: Unofficial PEAR meeting summary
| From: | Paul M Jones | Date: | Thu, 06 May 2004 23:38:39 +0000 |
| Subject: | Re: Unofficial PEAR meeting summary | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-28919@lists.php.net to get a copy of this message | ||
On May 6, 2004, at 6:36 PM, Daniel Convissor wrote:
On Thu, May 06, 2004 at 03:39:43PM -0500, Paul M Jones wrote:And there you have it. +1 for SSL encryption, even self-signed, on the XMLRPC authentication interface. Pair.com hosts the site, they may donate a certificate. -- Paul M. Jones Savant: the simple alternative to Smarty for PHP. http://phpsavant.com/ DB_Table: build RDBMS tables and XHTML forms in one PHP class. http://wiki.ciaweb.net/yawiki/index.php?area=DB_Table Yawiki: your collaborative online documentation system. http://wiki.ciaweb.net/yawiki/index.php?area=YawikiOn May 6, 2004, at 3:34 PM, Cipriano Groenendal wrote:It is not secure at all. When I first joined up, I was surprised to see that's the authentication method.However, we are not passing anything in the open, except for perhaps and md5sum of the password. This could be consideredsecureby most people , unless you're really paranoid :)It leaves open the possibility of a brute force dictionary attack,A dictionary attack isn't necessary. All a nepharious person needs to do is forge a cookie named PHP_USER and put the persons user name in and then forge another cookie named PEAR_PW and put the md5sum in it. Let alone, someone could snoop hits to login.php and grab the actual password.