doujing9972 2017-06-28 14:24
浏览 124
已采纳

PHP Radius密码嗅探

I recently wrote this piece of code:

$radius = radius_auth_open();
radius_add_server($radius, $serverIP, $port_no, 'secret', 5, 3);
radius_create_request($radius, RADIUS_ACCESS_REQUEST);
radius_put_attr($radius, RADIUS_USER_NAME, $username);
radius_put_attr($radius, RADIUS_USER_PASSWORD, $password);

$result = radius_send_request($radius);

switch ($result)
{
    case RADIUS_ACCESS_ACCEPT:
    // etc...

And my var $password is not encrypted at all, in fact, if I encrypt it with password_hash() radius won't recognize it.

Thus my question is:

Can a sniffer pick up that password? Or does radius_send_request already scramble it because of the parameter RADIUS_USER_PASSWORD?


EDIT:

I confused the terms hash and encrypt.

Radius does obfuscate the password when given the parameter attribute RADIUS_USER_PASSWORD. That is enough security for my system.

Thanks!

  • 写回答

1条回答 默认 最新

  • doukui7574 2017-06-28 18:12
    关注

    Radius does obfuscate the password when given the parameter attribute RADIUS_USER_PASSWORD.

    So nobody should be able to sniff your radius authentication

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 微信小程序协议怎么写
  • ¥15 c语言怎么用printf(“\b \b”)与getch()实现黑框里写入与删除?
  • ¥20 怎么用dlib库的算法识别小麦病虫害
  • ¥15 华为ensp模拟器中S5700交换机在配置过程中老是反复重启
  • ¥15 java写代码遇到问题,求帮助
  • ¥15 uniapp uview http 如何实现统一的请求异常信息提示?
  • ¥15 有了解d3和topogram.js库的吗?有偿请教
  • ¥100 任意维数的K均值聚类
  • ¥15 stamps做sbas-insar,时序沉降图怎么画
  • ¥15 买了个传感器,根据商家发的代码和步骤使用但是代码报错了不会改,有没有人可以看看