-
Notifications
You must be signed in to change notification settings - Fork 13
Open
Description
By the looks of it, all this code is doing is getting the username out of the NTLM request and verifying it's existance in an LDAP directory. There is no actual authentication - anyone can spoof a username over ldap, in fact any browser that prompts for a username will allow a user to "authenticate" as anyone they want.
Am I missing something?
Metadata
Metadata
Assignees
Labels
No labels