Re: Re: WAYS OF AUTHENICATION - open discussion

From: Date: Sun, 05 Nov 2000 21:17:32 +0000
Subject: Re: Re: WAYS OF AUTHENICATION - open discussion
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-23810@lists.php.net to get a copy of this message
I thought I'd put in my $0.02-worth on user authentication and share the method I use on my website. First, I store all user's passwords as md5-hashed strings in a mysql database. (I of course store usernames in the same table as the primary key.) My login page has a JavaScript source file that implements the md5 hash. (You can find it at <http://www.apt7.com/js/md5.js> and its web-viewable version at <http://www.apt7.com/js/md5.txt>.) My login form has a hidden form element called 'timestamp', which is, obviously, the string version of a Unix timestamp, and a hidden form element called 'login_hash'. The submit button for the form calls a JavaScript function called 'submit_form', which does the following: It does an md5 hash on the password. It concatenates the hashed password with the 'timestamp' and does an md5 hash on this string and assigns it to 'login_hash'. Then it sets the password form element of the form to "", and submits the form. Here's a little mock-up of the whole thing: // begin login.php <?php $time = time(); ?> <script language="JavaScript" src="md5.js"> </script> <script language="JavaScript"> <!-- // function submit_login() { // do some form validation here passhash = MD5(document.login.password.value); document.login.password.value = ""; passhash = MD5(passhash . document.login.timestamp.value); document.login.login_hash.value = passhash; document.login.submit(); return true; } // --> </script> <form name="login" method="login_handler.php" action="POST"> <input type="hidden" name="timestamp" value="<?php echo $time;?>"> <input type="hidden" name="login_hash" value=""> Username: <input type="text" name="username" value=""><br> Password: <input type="password" name="password" value=""><br> <input type="submit" value="Log in" onClick="submit_login(); return false;"> </form> // end login.php // begin login_handler.php <? $username = $HTTP_POST_VARS[username]; $login_hash = $HTTP_POST_VARS[login_hash]; $timestamp = $HTTP_POST_VARS[timestamp]; $real_pass_hash = // do database query to get the md5-hashed password from DB $real_login_hash = md5($real_pass_hash . $timestamp); if(strcmp($real_login_hash, $login_hash) == 0) { // authenticate the user } else { // don't authenticate the user } // end login_handler.php Now this takes care of several things: First, the user's password is not sent in plaintext. Second, the password hash that is sent is unique every time the user logs in. The only problem with this that I can see is the inherent flaw in the md5 cryptographic hash function that has come to light recently. You could substitute an sha1 hash instead of md5 hash if you wanted -- and if you have libmcrypt or something. Let me know what you think or if you find any flaws in this. Dean.

« previous php.general (#23810) next »