. Updated Daily. Editions SDA India   SDA Indonesia
BUSINESS ENTERPRISE SOLUTIONS ARCHITECTURE INFORMATION SECURITY WIRELESS & MOBILITY DATA & STORAGE DEVELOPMENT HARDWARE













News

Thursday, 17 May 2007

PHP SOAP Extension HTTP Authentication Weakness

 

 

Stefan Esser has reported a weakness in PHP, which can be exploited by malicious people to bypass certain security restrictions.

The weakness is caused due to the use of an uninitialized variable within the function 'make_http_soap_request()' of the SOAP extension when calling 'php_rand_r()' to generate the nonce for the digest authentication, which may result in a weak and predictable nonce.

This problem is fixed in the Concurrent Versions System (CVS) repository.

 

Read the Post

 
 
print save email comment

print

save

email

comment

 
 

Search SDA Asia

Free eNewsletter

SDA Asia Magazine Free Download
 
 
 
Copyright @ 2009 SDA Asia Magazine - All Right Reserved Privacy Policy | Terms of Use