RE: [PHP] Sessions / logins / cookies / security

From: Date: Tue, 16 Jul 2002 19:30:50 +0000
Subject: RE: [PHP] Sessions / logins / cookies / security
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-107958@lists.php.net to get a copy of this message
Anyone? Can someone at least point me to some web article for recommendations? I saw some examples where a password variable was stored, but is that really safe (as long as I MD5 it first?) Chad -----Original Message----- From: Chad Day [mailto:cday@atpco.com] Sent: Tuesday, July 16, 2002 12:30 PM To: php-general@lists.php.net Subject: [PHP] Sessions / logins / cookies / security I asked something similar a little while ago, but didn't do a good job clarifying. What I'm looking to do is when a user logs in, I start up the session.. I then have the registered session var to verify they are authenticated as they move throughout the site. Now, when they close the browser and come back, I want them to still be authenticated. Obviously, I have to set a cookie. But what do I set? Do I set just their user ID? The MD5 of their password? What's the most secure way, that's not easily spoofed? I don't know that much about cookies, but if I just use a user ID, couldn't someone just change that ID value and 'become' another user? Thanks for any advice, Chad -- PHP General Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php

« previous php.general (#107958) next »