Re: Re: WAYS OF AUTHENICATION - open discussion

From: Date: Sun, 05 Nov 2000 20:52:51 +0000
Subject: Re: Re: WAYS OF AUTHENICATION - open discussion
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-23808@lists.php.net to get a copy of this message
I'm not quite following you. I can't make comments about how secure your design is because I don't see the entire design. I have some reference session handeling code. It is small, but effective. The reason I say reference is because it is small -- should be easy to read through in a few minutes and understand. You take take a peek here: http://www.nirvani.net/software/j-sessions-1.0.0-pre1/ Hope this helps. -jeremy brand _______________________________________________________________________ GnuPG Fingerprint: 9F5E 95E0 1CC2 E054 84EA 6099 8ACD 9DBA D2C0 5EA9 _ http://www.JeremyBrand.com/Jeremy/Brand/Jeremy_Brand.html for more __ On Sun, 5 Nov 2000, Richard Creech - DreamRiver.com wrote: > Date: Sun, 05 Nov 2000 12:49:55 -0800 > From: Richard Creech - DreamRiver.com <richardc@dreamriver.com> > To: php-general@lists.php.net > Subject: [PHP] Re: WAYS OF AUTHENICATION - open discussion > > Hello, > I have a question about a third 'authentication' method I haven't seen discussed > in this thread. The method is hand rolled username / password combination using constants protected > by a transparent parsed include file like this: > > <?php include("util.php3"); ?> > > ... util.php3 contains this code: > > define("ADMINHOME", "admin.php3"); > define("ADMINUSER", "EnterAnAdminUserNameHere"); > > util.php3 is INSIDE the publicly accessible web tree ( a basedir restriction is in effect > preventing me from putting the file somewhere safer ) > > The files (just a few) are protected using this method by the conditional execution of a page > like this: > > <?php > if (($formuser != ADMINUSER) || ($formpassword != ADMINPASSWORD)){ > echo "<p class='accessdenied'>Access<br>denied.</p>"; > exit; > }else{ > // user is allowed in... > > My question for this list is what are the potential security risks with this method and how can > they be minimized? > > Kind Regards, > > Richard Creech > richardc@dreamriver.com Phone: 250.744.3350 Pacific Time Canada > Get a free link at http://www.dreamriver.com/phpYellow/ > Download phpYellow Pages 2000 - Now shipping Version 1.051 with EasySQL! > Add Dynamic Database Content to your Website > http://dreamriver.com/software/ > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > >

« previous php.general (#23808) next »