Re: security question
| From: | Raymund | Date: | Fri, 01 Sep 2000 08:09:18 +0000 |
| Subject: | Re: security question | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-14740@lists.php.net to get a copy of this message | ||
hi,
why do you don't try the phplib 7.x which has all this functions
implemented yet.
you can find it at: http://phplib.netuse.de/index.php3
RAY
venome@gmx.net schrieb:
>
> i am currently working on a security system to embed in any webpage that
> needs it.
>
> my question to all the experts out there is:
>
> is my project SAFE enough, or are there any evident security leaks? that
> is, i don't mean safe enough for things like credit card transactions, i mean
> safe enough to use it e.g. for an administration back-end (adding news and
> so on) for little commercial websites.
>
> here's how it works:
>
> the idea is that i have a class an instance of which is created on top of
> the protected page. then, a function of this class checks if there are two
> cookies already set, one containing the user name and the other one
> containing the password (md5 encoded). if so, access is granted, if not, a login
> screen appears that will set two variables (user name and password) and, when
> reloading, the cookies are set and therefore access will be granted.
>
> abstract code:
>
> <?
> $Login = new $LoginClass(...); # constructor sets cookies if form
> # variables are set
> if (!$Login->CheckUserID) # checks if the cookies or form variables
> # contain a valid
> # user name / pw combination,
>
> $Login->ShowLoginScreen; # displays form (two input fields that will
> # set the form variables)
>
> else { ?> # display the protected content
>
> <html>
> <header>
> ..
> </header>
> <body ..>
> ...
> </body ..>
> </html>
>
> <? } ?>
>
> thanks in advance for your judgement!
>
> --
> Sent through GMX FreeMail - http://www.gmx.net
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net