Re: security question
| From: | Wico de Leeuw | Date: | Fri, 01 Sep 2000 08:16:11 +0000 |
| Subject: | Re: security question | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-14738@lists.php.net to get a copy of this message | ||
Hiya
cookies can be retrieved bu hostile websites why don;t use sessions (sid) and store the sid/username/crypted password pair in a database
P.S. i recommend using crypt and storing only the crypt version of the password into the database
thatway when you server gets hacked (knoking off) they won't be able to get the passwords (a least not fast) better use mcrypt libary though :)Greetz, Wico At 10:01 1-9-00 +0200, venome@gmx.net wrote:
i am currently working on a security system to embed in any webpage that needs it. my question to all the experts out there is: is my project SAFE enough, or are there any evident security leaks? that is, i don't mean safe enough for things like credit card transactions, i mean safe enough to use it e.g. for an administration back-end (adding news and so on) for little commercial websites. here's how it works: the idea is that i have a class an instance of which is created on top of the protected page. then, a function of this class checks if there are two cookies already set, one containing the user name and the other one containing the password (md5 encoded). if so, access is granted, if not, a login screen appears that will set two variables (user name and password) and, when reloading, the cookies are set and therefore access will be granted. abstract code: <? $Login = new $LoginClass(...); # constructor sets cookies if form# variables are set if (!$Login->CheckUserID) # checks if the cookies or form variables # contain a valid # user name / pw combination,$Login->ShowLoginScreen; # displays form (two input fields that will # set the form variables)else { ?> # display the protected content.. ... <? } ?> thanks in advance for your judgement! -- Sent through GMX FreeMail - http://www.gmx.net -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net