News Feed
Sections




News Archive
Looking for more information on how to do PHP the right way? Check out PHP: The Right Way

Secunia.com:
PHP SOAP Extension HTTP Authentication Weak Nonce
May 16, 2007 @ 09:31:00

Secunia has a new advisory posted concerning an issue discovered with PHP's SOAP extension's HTTP authentication mechanism:

The weakness is caused due to the use of an uninitialized variable within the function "make_http_soap_request()" of the SOAP extension when calling "php_rand_r()" to generate the nonce for the digest authentication, which may result in a weak and predictable nonce.

The issue is marked as "less critical" but should still be taken into consideration. The issue has been corrected in the latest CVS commit.

1 comment voice your opinion now!
soap extension weak nonce phprandr cvs commit soap extension weak nonce phprandr cvs commit


blog comments powered by Disqus

Similar Posts

InformBank.com: How to create Microsoft Office documents on the fly using PHP

php|architect: The CodeWorks 2010 early-bird extended to October 4th (TODAY!)

Project: phpVirtualBox - VirtualBox Management Tool

Lukas Smith's Blog: PHP adopting branching kicking and screaming

Zend Developer Zone: Reading Access Databases with PHP and PECL


Community Events





Don't see your event here?
Let us know!


introduction opinion composer community framework library interview laravel conference security podcast voicesoftheelephpant version list symfony language release series artisanfiles tool

All content copyright, 2014 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework