Other nomination
Bypassing HTTP Basic Authenitcation in PHP Applications
An assessment of a PHP site whose admin area was protected only by Apache HTTP Basic auth. Because PHP passes unrecognised WebDAV-style verbs through to the script, a request using an invented method such as DAMMI reaches /backend with no credentials; a short Ruby Net::HTTPRequest subclass automates it. Recommends LimitExcept and real session checks.
Record
- Researcher
- Paolo Perego
- Published by
- armoredcode.com
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Paolo Perego, first published at the original source. Preserved copies are kept so the citation survives its host.