Re: security question

From: Date: Fri, 01 Sep 2000 08:09:18 +0000
Subject: Re: security question
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-14740@lists.php.net to get a copy of this message
hi, why do you don't try the phplib 7.x which has all this functions implemented yet. you can find it at: http://phplib.netuse.de/index.php3 RAY venome@gmx.net schrieb: > > i am currently working on a security system to embed in any webpage that > needs it. > > my question to all the experts out there is: > > is my project SAFE enough, or are there any evident security leaks? that > is, i don't mean safe enough for things like credit card transactions, i mean > safe enough to use it e.g. for an administration back-end (adding news and > so on) for little commercial websites. > > here's how it works: > > the idea is that i have a class an instance of which is created on top of > the protected page. then, a function of this class checks if there are two > cookies already set, one containing the user name and the other one > containing the password (md5 encoded). if so, access is granted, if not, a login > screen appears that will set two variables (user name and password) and, when > reloading, the cookies are set and therefore access will be granted. > > abstract code: > > <? > $Login = new $LoginClass(...); # constructor sets cookies if form > # variables are set > if (!$Login->CheckUserID) # checks if the cookies or form variables > # contain a valid > # user name / pw combination, > > $Login->ShowLoginScreen; # displays form (two input fields that will > # set the form variables) > > else { ?> # display the protected content > > <html> > <header> > .. > </header> > <body ..> > ... > </body ..> > </html> > > <? } ?> > > thanks in advance for your judgement! > > -- > Sent through GMX FreeMail - http://www.gmx.net > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#14740) next »