RE: [PHP-GENERAL] What about client side security?
| From: | Gustafson, Mårten | Date: | Thu, 15 Jun 2000 12:32:14 +0000 |
| Subject: | RE: [PHP-GENERAL] What about client side security? | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-1924@lists.php.net to get a copy of this message | ||
A good tutorial can be found @
http://www.builder.com/Programming/Scripter/013100/ss01.html
regards
--marten
> -----Original Message-----
> From: Markus [mailto:ravel@otitsun.oulu.fi]
> Sent: Thursday, June 15, 2000 1:29 PM
> To: php-general@lists.php.net
> Subject: [PHP-GENERAL] What about client side security?
>
>
> Hi,
>
> I'm building up a web site using PHP4&MySQL and I've been creating a
> comprehensive web based update utility for site admins. The
> server I'm using
> doesn't have SSL, so I've had to do some serious thinking in
> order to make
> the updating pages as secure as possible.
>
> I've read a lot of tutorials and articles on this matter and
> I've created a
> system that saves in the 'users' database only the md5 hash
> of the user's
> passwords and also takes advantage of PHP4's session
> management. However, if
> I've understood the process correctly, the password passes
> from the user's
> browser to PHP as plain text. Is there any other way to
> prevent this than
> using SSL?
>
> I've been wondering if some JavaScript md5'ing would do any good, but
> haven't yet managed to figure out how to use them most
> efficiently nor if
> this really helps me.
>
>
> .markus
>
> |-------------------------------------------|
> | A proud member of MS Site Builder Network |
> | since... er... 1996... *blush* |
> |-------------------------------------------|
>
>
>
>
>
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail:
> php-list-admin@lists.php.net
>