Re: WAYS OF AUTHENICATION - open discussion
| From: | Richard Creech - DreamRiver.com | Date: | Sun, 05 Nov 2000 20:49:55 +0000 |
| Subject: | Re: WAYS OF AUTHENICATION - open discussion | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-23806@lists.php.net to get a copy of this message | ||
Hello,
I have a question about a third 'authentication' method I haven't seen discussed in
this thread. The method is hand rolled username / password combination using constants protected by
a transparent parsed include file like this:
<?php include("util.php3"); ?>
... util.php3 contains this code:
define("ADMINHOME", "admin.php3");
define("ADMINUSER", "EnterAnAdminUserNameHere");
util.php3 is INSIDE the publicly accessible web tree ( a basedir restriction is in effect preventing
me from putting the file somewhere safer )
The files (just a few) are protected using this method by the conditional execution of a page like
this:
<?php
if (($formuser != ADMINUSER) || ($formpassword != ADMINPASSWORD)){
echo "<p class='accessdenied'>Access<br>denied.</p>";
exit;
}else{
// user is allowed in...
My question for this list is what are the potential security risks with this method and how can they
be minimized?
Kind Regards,
Richard Creech
richardc@dreamriver.com Phone: 250.744.3350 Pacific Time Canada
Get a free link at http://www.dreamriver.com/phpYellow/
Download phpYellow Pages 2000 - Now shipping Version 1.051 with EasySQL!
Add Dynamic Database Content to your Website
http://dreamriver.com/software/