What about client side security?
| From: | Markus | Date: | Thu, 15 Jun 2000 11:39:34 +0000 |
| Subject: | What about client side security? | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-1921@lists.php.net to get a copy of this message | ||
Hi,
I'm building up a web site using PHP4&MySQL and I've been creating a
comprehensive web based update utility for site admins. The server I'm using
doesn't have SSL, so I've had to do some serious thinking in order to make
the updating pages as secure as possible.
I've read a lot of tutorials and articles on this matter and I've created a
system that saves in the 'users' database only the md5 hash of the user's
passwords and also takes advantage of PHP4's session management. However, if
I've understood the process correctly, the password passes from the user's
browser to PHP as plain text. Is there any other way to prevent this than
using SSL?
I've been wondering if some JavaScript md5'ing would do any good, but
haven't yet managed to figure out how to use them most efficiently nor if
this really helps me.
.markus
|-------------------------------------------|
| A proud member of MS Site Builder Network |
| since... er... 1996... *blush* |
|-------------------------------------------|