Re: <form> security problem
| From: | Dean Hall | Date: | Fri, 13 Oct 2000 18:15:39 +0000 |
| Subject: | Re: <form> security problem | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-20049@lists.php.net to get a copy of this message | ||
First of all, don't forget to use <form method="post" ...>.
As for the security problem, I would need to know a bit more about what this
$test variable is. If it can be either "1" or "0", then the solution is
pretty simple:
Choose some secret key -- even something simple like something you might use
for a password would work. Concatenate this key with the value for $test and
hash it with md5. Then a.php can test whether the hash is good for 0 or 1.
Something like this:
Your form:
<form action="a.php" method="post">
<input name="test" type="text" value="<?=md5($key .
"0")?>">
<input type="submit">
</form>
a.php:
$zero_hash = md5($key, "0");
$one_hash = md5($key, "1");
if($HTTP_POST_VARS[test] == $zero_hash) {
// do something for a "0" value
}
else if($HTTP_POST_VARS[test] == $one_hash) {
// do something for a "1" value
}
else {
// the user messed with the form value, do something else
}
Now, you would need to keep the value of $key pretty secure if you're
concerned about security, but this should work.
If "test" can have other values, there are other ways to solve this problem.
I've just implemented a login system on my site that is unencrypted but
prevents sending plaintext or even simple hashed passwords -- passwords are
sent hashed with a one-time pad -- a cryptographically unique value -- and
then sent to my server.
If you need more help, I'd be glad to try.
Dean.
----- Original Message -----
From: "Vojtěch Patrný" <patrnyv@yahoo.com>
To: <php-general@lists.php.net>
Sent: Friday, October 13, 2000 11:51 AM
Subject: [PHP] <form> security problem
> Hi,
> I`ve a problem with my php app.
>
> I use this code :
> (form action="a.php")
> (input name="test" type="text" value="0")
> (input type="submit")
> (/form)
>
> The problem is that anybody can save this page on
> his computer and edit the value="xx" and then send
> it to my DB. I need to filter if it cames from my site.
> Can somebody help me please?
>
> Data in value change every time so it`s
> imposible to make a db filter.
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net