Re: WAYS OF AUTHENICATION - open discussion

From: Date: Sat, 04 Nov 2000 09:45:36 +0000
Subject: Re: WAYS OF AUTHENICATION - open discussion
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-23691@lists.php.net to get a copy of this message
>Don't make mysql users. That is wrong. I don`t, but I do know people who make. What is so bad about? Of course, when there will be very many users..but why this is so bad solution? >The first and second ideas are the correct ones whether you do hand >written sessions or use PHP4. The part that I think you are missing >is that the "session" is a unique key so to speak that lets the user >be active. I understand that. I have used it myself:-) But probably I just didn´t make myself clear enough. >Another part is that this table that holds the sessions >usually gets cleaned out by something running in cron -- basically >nuking any "expired" sessions. In my case, this is cleaned usually by a logout button or in case someone exits in some otehr way, the session will be deleted when someone activates the login page again. >This prevents what you have >stated, that if soneone knew the session, they can get in. I`m not talkin about people to get to know the sessions, but rather usernames and passwords. For example: lets say that I have a file called connect.inc.php3 and I have included to every page that I have. The file itself contains the following information: $db = mysql_connect("somehost","someuser","somepass"); Now when somone knows the filename (inthis case connect.inc.php3) and he knows the variable name (in this case $db), he can include theinc file in his own page and echo the $db and so getting to know the mysql user information. Siim Einfeldt

« previous php.general (#23691) next »