RE: [PHP] security question
| From: | Maxim Maletsky | Date: | Fri, 01 Sep 2000 09:52:09 +0000 |
| Subject: | RE: [PHP] security question | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-14767@lists.php.net to get a copy of this message | ||
The code I gave to you is the one I used while working on a statistic
software, It check whether what sent you to this page was a file from your
site or not, and eventually if not then remember the full URL of the website
but if page is mine then creates a map. (like user's adventures on my
website)
Now sessions, are still using cookies but they are hosted on the server
instead your browser.
It's too long to describe them, but you really should start using them, and
it's easier to work with, (the codes are kinda simplier)
Try to follow some instructions on php.net ( ww2.php.net ) or any other
tutorial..
for example:
session start()
if (!isset($myVar))
session register(myVar)
so that if there's no such a session yet it will register the variable
called myVar as soon as it find it somewhere later.
Sessions MUST above any output of your current file.
They are pretty cool...
I'll review your code, and will give you a feedback,
Ironicaly, very soon I will to write a class for a password protected area,
so we could maybe exchange some ideas if you wish.
Cheers!
-----Original Message-----
From: Samuel Lüscher [mailto:samuel.luescher@gmx.net]
Sent: Friday, September 01, 2000 6:33 PM
To: Maxim Maletsky
Subject: RE: [PHP] security question
> I pretty much like the idea of the script you wrote, but it is much
> better
> use sessions
sounds interesting! can you give me some more information about that,
please? what exactly are sessions, what's the difference to cookies, how do
i
use them?
> and
> I think once the cookies are set you should also start checking for the
> referrer. Just to be sure that he log on while being on your website.
>
> maybe by having something like this in your class:
>
>
> if (isset($myCookie) && substr ($HTTP_REFERER, 0, (strlen($HTTP_HOST) +
> 7))
> == 'http://'.$HTTP_HOST)
so that would check if the user who's requesting the page actually IS on
my page and doesn't try to access from elsewhere?
> $referer =1;
i.e., everything is ok?
> else
> echo 'Login';
otherwise, this one is NOT friendly, show login screen?
>
> What do you think?
>
>
> -----Original Message-----
> From: venome@gmx.net [ <mailto:venome@gmx.net>
> mailto:venome@gmx.net]
> Sent: Friday, September 01, 2000 5:01 PM
> To: php-general@lists.php.net
> Subject: [PHP] security question
>
>
> i am currently working on a security system to embed in any webpage that
> needs it.
>
> my question to all the experts out there is:
>
> is my project SAFE enough, or are there any evident security leaks? that
> is, i don't mean safe enough for things like credit card transactions, i
> mean
> safe enough to use it e.g. for an administration back-end (adding news
> and
> so on) for little commercial websites.
>
> here's how it works:
>
> the idea is that i have a class an instance of which is created on top
> of
> the protected page. then, a function of this class checks if there are
> two
> cookies already set, one containing the user name and the other one
> containing the password (md5 encoded). if so, access is granted, if not,
> a
> login
> screen appears that will set two variables (user name and password) and,
> when
> reloading, the cookies are set and therefore access will be granted.
>
> abstract code:
>
> <?
> $Login = new $LoginClass(...); # constructor sets cookies if form
> # variables are set
> if (!$Login->CheckUserID) # checks if the cookies or form variables
> # contain a valid
> # user name / pw combination,
>
> $Login->ShowLoginScreen; # displays form (two input fields that
> will
> # set the form variables)
>
> else { ?> # display the protected content
>
> <html>
> <header>
> .
> </header>
> <body ..>
> ..
> </body ..>
> </html>
>
> <? } ?>
>
> thanks in advance for your judgement!
>
> --
> Sent through GMX FreeMail - <http://www.gmx.net>
> http://www.gmx.net
>
>
> --
> PHP General Mailing List ( <http://www.php.net/>
> http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>
>
--
Sent through GMX FreeMail - http://www.gmx.net