Re: security flaw with smart http
- From
- Ivan Kanis <ivan.kanis@googlemail.com>
- Date
- Jun 28, 2012, 07:35 UTC
- Message-ID
- <87obo3j3d0.fsf@visionobjects.com>
- In-Reply-To
- <7vmx3vp2co.fsf@alter.siamese.dyndns.org>
Junio C Hamano <gitster@pobox.com> a écrit
Show 12 quoted lines
> Shawn Pearce <spearce@spearce.org> writes: > >> On Fri, Jun 22, 2012 at 3:12 AM, Ivan Kanis <ivan.kanis@googlemail.com> wrote: >>> I think we found a security flaw with git http smart backend. We are >>> running git version 1.0.7.4 on our server. Adding random words after the >>> password and the authentication still succeeds. >> >> git http-backend does not handle authentication or authorization. This >> is handled in your web server. You should consult your web server's >> documentation, and maybe its configuration files. > > Very good advice.
In case someone is reading this thread I confirm the problem comes from Apache.
--
Ivan Kanis, Release Manager, Vision Objects,
Le mal est un mulet : il est opiniâtre et stérile.
-- Victor Hugo