[Icecast] icecast_auth (url authentication)

oddsock oddsock at oddsock.org
Mon Jan 16 14:37:20 UTC 2006


At 06:02 AM 1/16/2006, Klauss Fumuldavijus wrote:
>has anyone tried $subj php scripts located in /examples/ dir?
>in my case any authorisation of protected mount seems to be bypassed 
>without any checks. Without any logins or passwords i can listen to 
>locked stream.
>

This has been reported before, however it's has ALWAYS been due to 
caching of the data in the media player.  Winamp, for instance, 
caches your username and password in the request, so usually you just 
have to enter the user/pass once and from that time forward it may 
*seem* that you are bypassing the user/pass check, however icecast 
still validates it.  Try using something like "wget" (which doesn't 
cache user/passwords for http authenticated streams)

oddsock 





More information about the Icecast mailing list