Two questions about security
| From: | Siim Einfeldt aka Itpunk | Date: | Sat, 04 Nov 2000 14:31:37 +0000 |
| Subject: | Two questions about security | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23712@lists.php.net to get a copy of this message | ||
1. When user logs in to the page, I can add the sessionid,useragent and ip
to the database for identifying the user later. Is there any more
predefined variables that I could add to the database for checking, just
to make the thing more secure?
2. When user logs in, he enters his username and password, at this time,
when he enters the submit button, how easy it is for hackers to get
his password 'on the fly' before I get the chance to encrypt it? And
how could I make it more secure?
Siim Einfeldt
P.S Like before, I`d appreciate a copy to my private email too.