Re: WAYS OF AUTHENICATION - open discussion
| From: | Thomas Deliduka | Date: | Sun, 05 Nov 2000 04:21:57 +0000 |
| Subject: | Re: WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23766@lists.php.net to get a copy of this message | ||
If the file that is included is not in the public portion of the server then
it can't be included from remote, thus not gaining access to the mysql
database.
for instance, if your public directory is in:
/home/theuser/www
And the include file is /home/theduke/include/connect.inc.php3
You include the file in your script and it prevents someone from outside of
the server having access to it.
The 'session' information stored in the db table has a timestamp on it and
the cron removes it after the specified time, the username is only stored in
there. Each user has a 2 hour window, after two hours the system will see
the timestamp has expired and tell them to re-login, so even if the cron
hasn't removed the session information, the script knows to not accept a
session after two hours.
Also, when I store passwords in a database I encode them using the MySQL
encode function ENCODE(str,pass_str)
(http://www.mysql.com/documentation/mysql/bychapter/manual_Reference.html#Mi
scellaneous_functions)
This value is stored as a BLOB in the table so it's encoded nicely, AND I
encode the password with itself so if the password was 'jones' then I do
password = encode('jones','jones'). This way nobody but the user who knows
the password can possibly retrieve it. There is no external 'key' that
someone can find.
The drawback? Well, if they forget their password then it can't be retrieved
so I generate a new one randomly generated and sent to the e-mail on file
(retrieved by user giving username so they don't know what e-mail address
the new password was sent to). After they get the randomly generated
password they are encouraged to login and change the password again to what
they want.
Additional drawback to this, I have a user who continually forgets what
password she uses and in two months she's reset it 2 times.
Just my 2 cents worth. Feel free to poke holes in my methodology and tell me
why it wouldn't work.
On 11/4/00 4:45 AM this was written:
> I`m not talkin about people to get to know the sessions, but rather
> usernames and passwords. For example: lets say that I have a file called
> connect.inc.php3 and I have included to every page that I have. The file
> itself contains the following information:
> $db = mysql_connect("somehost","someuser","somepass");
> Now when somone knows the filename (inthis case connect.inc.php3) and he
> knows the variable name (in this case $db), he can include theinc file in
> his own page and echo the $db and so getting to know the mysql user
> information.
--
Thomas Deliduka
IT Manager
-------------------------
New Eve Media
The Solution To Your Internet Angst
http://www.neweve.com/