Re: Encrypt in Javascript and Decrypt in PHP????
| From: | Scott Fletcher | Date: | Mon, 13 Jan 2003 14:56:48 +0000 |
| Subject: | Re: Encrypt in Javascript and Decrypt in PHP???? | ||
| References: | 1 2 3 4 5 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-131439@lists.php.net to get a copy of this message | ||
Yea, the hacker would guess a random number in html & javascript but the
hacker have no way of putting it into php on the server-side. So, we get
two different random number and a invalid match.
"Marek Kilimajer" <kilimajer@webglobe.sk> wrote in message
news:3E228A71.8020203@webglobe.sk...
> This has been solved - the extra characters are stored in session,
> otherwise attacker can repeat it too. Password can be stored on
> the server using one way has - on the client the script hashes
> twice, first to get hashed password, then together with random
> string
>
> Gerald Timothy Quimpo wrote:
>
> >On Saturday 11 January 2003 12:12 am, Scott Fletcher wrote:
> >
> >
> >>The only thing that is important to me is that the password get
> >>encrypted before transmitting across the internet.
> >>
> >>
> >
> >from other posts further in the thread it looks like you aren't
> >ready to use https. that's too bad. that would really be the
> >right solution.
> >
> >but since you must hash, one problem with hashing is, it is still
> >necessary to have the hash vary from one invocation to another.
> >otherwise, if the hash is the same every time the user logs in
> >(i.e., if all you do is take the password and run it through md5),
> >then anyone who can sniff the hash will be able to replay a login.
> >
> >unfortunately, if you want the hash to be different from one
> >invocation to the next, then the password cannot be stored
> >on the server as a one-way hash. instead, it would be either
> >plaintext or encrypted on the server. this way, when you
> >want to send the hash over the internet, instead of just hashing
> >the password, you can generate a few extra characters. append
> >(or prepend) the characters to the password. then hash the
> >whole thing.
> >
> >then, when you send the hash over, send the extra characters
> >too. on the server side, you would then take the password from
> >the database (or wherever), decrypt it (if it's encrypted), append
> >or prepend the extra characters, hash the whole thing, and
> >compare the hashes.
> >
> >tiger
> >
> >
> >
>