Re: Unofficial PEAR meeting summary
| From: | Yavor Shahpasov | Date: | Fri, 07 May 2004 07:41:27 +0000 |
| Subject: | Re: Unofficial PEAR meeting summary | ||
| References: | 1 2 3 4 5 6 7 8 9 10 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-28927@lists.php.net to get a copy of this message | ||
Is there an alternative method of checking login via RPC. A login or authorize method would be usefull.
Not that anyone uses Auth/Container/Pear AFAIK
Yavor
Martin Jansen wrote:
On Thu May 06, 2004 at 10:3433PM +0200, Cipriano Groenendal wrote:-- Yavor Shahpasov yavo@siava.org Linux is not The Answer. Yes is the answer. Linux is The Question.If you look at Auth/Container/PEAR.php, you'll see that the Auth package uses an RPC call to get userinfo. Within taht is the md5sum of the pass, which is compared to a locally md5'd password string. Wether this is by design, or a bug, in cases like this it's quite cool :)That's definitively a bug! If I don't hear any *good* objections, I'll remove the password from the return value of user.info at the weekend.However, we are not passing anything in the open, except for perhaps and md5sum of the password. This could be consideredI don't think one needs to be paranoid to consider this insecure.secureby most people , unless you're really paranoid :)