Added password logic, now can't get the Authorization: check to trigger

Steve Langasek vorlon at netexpress.net
Wed Jul 26 14:10:32 GMT 2000


On Wed, 26 Jul 2000, Ron Alexander wrote:

> >From the cgi.log

> [Date: Wed, 26 Jul 2000 08:55:50 edt   24.66.96.61.on.wave.home.com
> (24.66.96.61)]
> GET / HTTP/1.1
> Accept: */*
> Accept-Language: en-ca
> Accept-Encoding: gzip, deflate
> User-Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 4.0; AtHome0101)
> Host: 134.111.220.160:901
> Connection: Keep-Alive

> [Date: Wed, 26 Jul 2000 08:56:28 edt   24.66.96.61.on.wave.home.com
> (24.66.96.61)]
> GET / HTTP/1.1
> Accept: */*
> Accept-Language: en-ca
> Accept-Encoding: gzip, deflate
> User-Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 4.0; AtHome0101)
> Host: 134.111.220.160:901
> Connection: Keep-Alive
> Authorization: Basic cm9vdDpyb290			<<<<<<<<<<<<< shouldn't this trigger the
> code above?

> BTW, what the heck is the cm9vdDpyb290 anyway?

'cm9vdDpyb290' should be the obfuscated (not encrypted) password being used
for authentication.  I'm curious that there's no username listed on that line.
I could easily be mistaken, but I thought the syntax is
  Authorization: <type> <user> <pass>

Your other logs from swat corroborate this, as it seems to be trying all your
share names looking for a username it can use with that password..?

Steve Langasek
postmodern programmer






More information about the samba-technical mailing list