Received: by taz.hyperreal.com (8.8.4/V2.0) id IAA00281; Wed, 12 Mar 1997 08:47:01 -0800 (PST) Received: from mrelay.jrc.it by taz.hyperreal.com (8.8.4/V2.0) with SMTP id IAA00241; Wed, 12 Mar 1997 08:46:55 -0800 (PST) Received: from jrc.it (elect6.jrc.it) by mrelay.jrc.it (4.1/EB-950131-C) id AA18270; Wed, 12 Mar 97 17:52:53 +0100 Received: by jrc.it (5.x/EB-950213-L) id AA15878; Wed, 12 Mar 1997 17:45:43 +0100 Date: Wed, 12 Mar 1997 17:45:43 +0100 From: "Dirk.vanGulik" Message-Id: <9703121645.AA15878@ jrc.it> To: new-httpd@hyperreal.com, ben@syd.au.swissbank.com Subject: Re: [BUG]: "authentication bypassed by MSIE 3.01 users" on Solaris 2.x (fwd) X-Sun-Charset: US-ASCII Sender: new-httpd-owner@apache.org Precedence: bulk Reply-To: new-httpd@hyperreal.com I have some trouble believing this; and reproducing; what I can reproduce is 1. if you have the page in the cache and press cancel/ abort or enter a wrong password and press cancel, you will see the cahced page; even if you request it to be explicitly cheched. The entry in the log (if the RQ makes it, is just a AuthRQ. 2. if you press cancel on old versions of MSIE, and you have the save passwd on; it will use that (but you get the right entry in the logfile) 3. If is easy to make a dbm file with two null entries and thus allow in a null passwd. DW. > Please tell me he's mistaken. This sounds too stupid to be true. > > > ---------- Forwarded message ---------- > Date: Tue Mar 11 21:12:48 1997 > From: ben@syd.au.swissbank.com > To: apache-bugs%apache.org@organic.com > Subject: [BUG]: "authentication bypassed by MSIE 3.01 users" on Solaris 2.x > > Submitter: ben@syd.au.swissbank.com > Operating system: Solaris 2.x, version: > Version of Apache Used: 1.2b4 > Extra Modules used: > URL exhibiting problem: > > Symptoms: > -- > Users of MS IE 3.01 (on NT 4.0) are able to > bypass authentication by pressing the cancel button > when asked to supply a user name and password. > > Apache serves the pages, and writes a blank in > the access log as the auth user. (Rather than the > "-" for an unknown user.) > > Other versions of MS IE, and other brosers are not > able to do this. (They get an "authorisation > failed" error message) > > This is not listed in the bug list. I am upgrading > to 1.2b7 to see if it exhibits the problem. > -- > > Backtrace: > -- > > -- > > >