Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




Vulnerability Development mailing list archives

Re: remote_user and apache
From: Holger van Koll <holger () VANKOLL DE>
Date: Wed, 2 Aug 2000 20:03:01 +0200

David Augros wrote:

Sorry if this is offtopic, but I figure it's close enough to try.

Does anybody know how basic http auth is handled (in particular, by
apache)?
In short: If apache finds any instruction that the accessed page is
protected (f.e. a .htaccess file),
it asks for username/pwd for every request. The browser also sends it
every time again
(however it does only prompt you one time).

Specifically, I am interested in the env variable 'remote_user'
This variable is set by httpd , not sent by the browser (as most
others), so...

My interest is in whether the 'remote_user' variable is trustworthy
... it´s not easy to forge. A
http://somewhere/something.html?remote_user=bla won´t forge it.

I would trust it.


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]