Current time: 05-04-2024, 02:49 PM Hello There, Guest! (LoginRegister)


Post Reply 
PMA Security vulnerability ?
Author Message
BeNe Offline
Moderator
*****
Moderators

Posts: 5,899
Joined: Jan 2007
Reputation: 68
Post: #1
Question PMA Security vulnerability ?
Hello,

i checked my config.inc.php in my PMA directory.
There is per default the blowfish_secret set:

Code:
/* YOU MUST FILL IN THIS FOR COOKIE AUTH! */
$cfg['blowfish_secret']                 = 'VhCsOm3g4kl631po0em3x33g1b.nehir3';

I check the file in the trunk, and this "blowfish_secret" string is in every ispCP installation on every Server the same?

I read about it in the PMA Docu

Code:
$cfg['blowfish_secret'] string
The "cookie" auth_type uses blowfish algorithm to encrypt the password.
If you are using the "cookie" auth_type, enter here a random passphrase of your choice. It will be used internally by the blowfish algorithm: you won’t be prompted for this passphrase. The maximum number of characters for this parameter seems to be 46.

ispCP is using the "cookie" auth_type.
So i dont know if this is a Security vulnerability or not ?
I use PMA of course, but i don´t no much about this function...

Greez BeNe

The secons thing is, i can see here "vhcs" in the key --> "VhCsOm3g4kl631po0em3x33g1b.nehir3" Wink
(This post was last modified: 05-30-2007 07:13 PM by BeNe.)
05-30-2007 07:11 PM
Visit this user's website Find all posts by this user Quote this message in a reply
Post Reply 


Messages In This Thread
PMA Security vulnerability ? - BeNe - 05-30-2007 07:11 PM
RE: PMA Security vulnerability ? - joximu - 05-30-2007, 07:47 PM
RE: PMA Security vulnerability ? - BeNe - 05-30-2007, 11:34 PM
RE: PMA Security vulnerability ? - RatS - 05-31-2007, 02:22 AM
RE: PMA Security vulnerability ? - BeNe - 05-31-2007, 02:40 AM
RE: PMA Security vulnerability ? - joximu - 05-31-2007, 03:23 AM
RE: PMA Security vulnerability ? - RatS - 05-31-2007, 07:30 AM
RE: PMA Security vulnerability ? - joximu - 05-31-2007, 08:33 AM
RE: PMA Security vulnerability ? - raphael - 05-31-2007, 10:17 AM
RE: PMA Security vulnerability ? - raphael - 05-31-2007, 11:22 AM
RE: PMA Security vulnerability ? - joximu - 05-31-2007, 05:07 PM
RE: PMA Security vulnerability ? - BeNe - 05-31-2007, 11:12 PM
RE: PMA Security vulnerability ? - raphael - 06-01-2007, 10:21 AM

Forum Jump:


User(s) browsing this thread: 1 Guest(s)