Web Hack List

Collected research

Bypassing HTTP Basic Authenitcation in PHP Applications

Bypassing HTTP Basic Authentication in PHP applications

An assessment of a PHP site whose admin area was protected only by Apache HTTP Basic auth. Because PHP passes unrecognised WebDAV-style verbs through to the script, a request using an invented method such as DAMMI reaches /backend with no credentials; a short Ruby Net::HTTPRequest subclass automates it. Recommends LimitExcept and real session checks.

Record

Document
Bypassing HTTP Basic Authentication in PHP applications
Researcher
Paolo Perego
Published by
armoredcode.com
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Paolo Perego, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .