Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




Vulnerability Development mailing list archives

Re: remote_user and apache
From: PCbob - Slobodan miskoviC <Yugoslavia () CANADA COM>
Date: Wed, 2 Aug 2000 09:50:06 -0700

David Augros wrote:

My interest is in whether the 'remote_user' variable is trustworthy
enough to decide that we are dealing with an authenticated user who is
not faking his login name. Any insights/pointers are welcome.

    The remote_user variable is used for browser authentication, and i do
not see any use of spoofing username as server requires password every
time. You are probably thinking that remote user gives you the username on
client machine, which is wrong. So if user is "spoofing" his username he
must "spoof" his password too, which would me he found out someone else's
login data.

    cheer


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]