Re: WAYS OF AUTHENICATION - open discussion

From: Date: Sun, 05 Nov 2000 04:21:57 +0000
Subject: Re: WAYS OF AUTHENICATION - open discussion
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-23766@lists.php.net to get a copy of this message
If the file that is included is not in the public portion of the server then it can't be included from remote, thus not gaining access to the mysql database. for instance, if your public directory is in: /home/theuser/www And the include file is /home/theduke/include/connect.inc.php3 You include the file in your script and it prevents someone from outside of the server having access to it. The 'session' information stored in the db table has a timestamp on it and the cron removes it after the specified time, the username is only stored in there. Each user has a 2 hour window, after two hours the system will see the timestamp has expired and tell them to re-login, so even if the cron hasn't removed the session information, the script knows to not accept a session after two hours. Also, when I store passwords in a database I encode them using the MySQL encode function ENCODE(str,pass_str) (http://www.mysql.com/documentation/mysql/bychapter/manual_Reference.html#Mi scellaneous_functions) This value is stored as a BLOB in the table so it's encoded nicely, AND I encode the password with itself so if the password was 'jones' then I do password = encode('jones','jones'). This way nobody but the user who knows the password can possibly retrieve it. There is no external 'key' that someone can find. The drawback? Well, if they forget their password then it can't be retrieved so I generate a new one randomly generated and sent to the e-mail on file (retrieved by user giving username so they don't know what e-mail address the new password was sent to). After they get the randomly generated password they are encouraged to login and change the password again to what they want. Additional drawback to this, I have a user who continually forgets what password she uses and in two months she's reset it 2 times. Just my 2 cents worth. Feel free to poke holes in my methodology and tell me why it wouldn't work. On 11/4/00 4:45 AM this was written: > I`m not talkin about people to get to know the sessions, but rather > usernames and passwords. For example: lets say that I have a file called > connect.inc.php3 and I have included to every page that I have. The file > itself contains the following information: > $db = mysql_connect("somehost","someuser","somepass"); > Now when somone knows the filename (inthis case connect.inc.php3) and he > knows the variable name (in this case $db), he can include theinc file in > his own page and echo the $db and so getting to know the mysql user > information. -- Thomas Deliduka IT Manager ------------------------- New Eve Media The Solution To Your Internet Angst http://www.neweve.com/

« previous php.general (#23766) next »