Re: login scripts not secure?? help!

From: Date: Tue, 23 Mar 2004 17:19:23 +0000
Subject: Re: login scripts not secure?? help!
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-181285@lists.php.net to get a copy of this message
--- Andy B <aborka1@wmis.net> wrote: > i run into the deal where most login scripts check to see if > $_SESSION[username] or a $_SESSION var has been set or is valid. > i noticed this could be a very bad thing because there is nothing > stopping an outside link from doing something like: > <a > href="securepage.php?_SESSION[username]=admin&_SESSION[pwd]=password">go > to secure page</a> > and being valid (that is if they manage to hack the user/pwd)... Not to be rude, but it looks like you're just making stuff up. Did you try this? The $_SESSION array is "safe" in the sense that a user cannot directly manipulate it. Chris ===== Chris Shiflett - http://shiflett.org/ PHP Security - O'Reilly Coming Fall 2004 HTTP Developer's Handbook - Sams http://httphandbook.org/ PHP Community Site http://phpcommunity.org/

« previous php.general (#181285) next »