Forum Discussion

Altera_Forum's avatar
Altera_Forum
Icon for Honored Contributor rankHonored Contributor
19 years ago

ATHTTPD Authorization Bugs and Failures

ATHTTPD is parsing both BASIC and MD5 authorization headers improperly, causing it to ignore remainder of header (at best) and conclude any included POST information is invalid.

See my ATHTTPD reports at bugzilla for further discussion on fairly easy fix.

Several security flaws raised too.

Problem will manifest itself as bizarre browser behavior after responding to login and "400 Bad response" errors on subsequent POSTS.
No RepliesBe the first to reply