Re: login scripts not secure?? help!
| From: | Chris Shiflett | Date: | Tue, 23 Mar 2004 17:19:23 +0000 |
| Subject: | Re: login scripts not secure?? help! | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-181285@lists.php.net to get a copy of this message | ||
--- Andy B <aborka1@wmis.net> wrote:
> i run into the deal where most login scripts check to see if
> $_SESSION[username] or a $_SESSION var has been set or is valid.
> i noticed this could be a very bad thing because there is nothing
> stopping an outside link from doing something like:
> <a
> href="securepage.php?_SESSION[username]=admin&_SESSION[pwd]=password">go
> to secure page</a>
> and being valid (that is if they manage to hack the user/pwd)...
Not to be rude, but it looks like you're just making stuff up. Did you try
this? The $_SESSION array is "safe" in the sense that a user cannot
directly manipulate it.
Chris
=====
Chris Shiflett - http://shiflett.org/
PHP Security - O'Reilly
Coming Fall 2004
HTTP Developer's Handbook - Sams
http://httphandbook.org/
PHP Community Site
http://phpcommunity.org/