Re: Unofficial PEAR meeting summary

From: Date: Fri, 07 May 2004 06:59:44 +0000
Subject: Re: Unofficial PEAR meeting summary
References: 1 2 3 4 5 6 7 8 9 10  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-28926@lists.php.net to get a copy of this message
> On Thu May 06, 2004 at 10:3433PM +0200, Cipriano Groenendal wrote: > > If you look at Auth/Container/PEAR.php, you'll see that the Auth package > > uses an RPC call to get userinfo. Within taht is the md5sum of the pass, > > which is compared to a locally md5'd password string. Wether this is by > > design, or a bug, in cases like this it's quite cool :) > > That's definitively a bug! If I don't hear any *good* objections, I'll > remove the password from the return value of user.info at the weekend. Well, the only objection against that that I can think off, would be that it breaks anything using Auth_PEAR, such as Paul's Yawiki for pear-dev only... However, with DancielC's explanation of how to forge the cookies saying you only need an md5sum + username like he said earlier... I'd have to agree it's way to insecure right now to leave the md5's open like that. As such, blocking it off would probably be the best solution right now. Too bad for Auth_PEAR, but c'est la vie... Besides, I already have all your md5's anyway All your package are belong to me </jk> Cipri

« previous php.pear.dev (#28926) next »