LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > Bug Reports > 404 checked before checking authentication

Reply
 
Thread Tools Display Modes
  #1  
Old 04-17-2006, 02:02 PM
ts77 ts77 is offline
Senior Member
 
Join Date: Nov 2004
Posts: 288
Default 404 checked before checking authentication

Hi there,

I just found by accident that if I try to access some nonexistent file in a secured directory I get a 404 error message. if I try to access an existing file I get the authentication box.
That makes it possible for an attacker to find out which files exist in a directory even before going through authentication.
Therefore I think it would be much better to check authentication before trying to retrieve a file.
Reply With Quote
  #2  
Old 04-19-2006, 10:33 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,590
That's because of the "Files" directive support. Will try to address this in next release. :-)
Reply With Quote
  #3  
Old 05-15-2006, 05:02 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,590
Forgot to fix this in 2.1.15, should be fixed in 2.1.16 release.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
ERROR [ADMIN] authentication failed! superbarre.com Install/Configuration 6 11-21-2011 02:34 AM
Problem installing PHP/LSAPI Dondi PHP 11 06-03-2008 09:01 AM
Rails, LSAPI, Rewrites, Contexts, Authentication mabonyi Install/Configuration 2 02-11-2007 06:10 PM
How do I add users to authentication realms? travisbell Install/Configuration 3 01-27-2007 01:33 PM
MySQL Authentication rsilva Feedback/Feature Requests 3 08-11-2006 09:38 PM


All times are GMT -7. The time now is 10:11 PM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.