Re: Re: WAYS OF AUTHENICATION - open discussion
| From: | Dean Hall | Date: | Sun, 05 Nov 2000 21:17:32 +0000 |
| Subject: | Re: Re: WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23810@lists.php.net to get a copy of this message | ||
I thought I'd put in my $0.02-worth on user authentication and share the
method I use on my website.
First, I store all user's passwords as md5-hashed strings in a mysql
database. (I of course store usernames in the same table as the primary
key.)
My login page has a JavaScript source file that implements the md5 hash.
(You can find it at <http://www.apt7.com/js/md5.js> and its web-viewable
version at <http://www.apt7.com/js/md5.txt>.)
My login form has a hidden form element called 'timestamp', which is,
obviously, the string version of a Unix timestamp, and a hidden form element
called 'login_hash'. The submit button for the form calls a JavaScript
function called 'submit_form', which does the following: It does an md5 hash
on the password. It concatenates the hashed password with the 'timestamp'
and does an md5 hash on this string and assigns it to 'login_hash'. Then it
sets the password form element of the form to "", and submits the form.
Here's a little mock-up of the whole thing:
// begin login.php
<?php
$time = time();
?>
<script language="JavaScript" src="md5.js">
</script>
<script language="JavaScript">
<!-- //
function submit_login() {
// do some form validation here
passhash = MD5(document.login.password.value);
document.login.password.value = "";
passhash = MD5(passhash . document.login.timestamp.value);
document.login.login_hash.value = passhash;
document.login.submit();
return true;
}
// -->
</script>
<form name="login" method="login_handler.php" action="POST">
<input type="hidden" name="timestamp" value="<?php echo
$time;?>">
<input type="hidden" name="login_hash" value="">
Username: <input type="text" name="username" value=""><br>
Password: <input type="password" name="password"
value=""><br>
<input type="submit" value="Log in" onClick="submit_login(); return
false;">
</form>
// end login.php
// begin login_handler.php
<?
$username = $HTTP_POST_VARS[username];
$login_hash = $HTTP_POST_VARS[login_hash];
$timestamp = $HTTP_POST_VARS[timestamp];
$real_pass_hash = // do database query to get the md5-hashed password from
DB
$real_login_hash = md5($real_pass_hash . $timestamp);
if(strcmp($real_login_hash, $login_hash) == 0) {
// authenticate the user
}
else {
// don't authenticate the user
}
// end login_handler.php
Now this takes care of several things:
First, the user's password is not sent in plaintext.
Second, the password hash that is sent is unique every time the user logs
in.
The only problem with this that I can see is the inherent flaw in the md5
cryptographic hash function that has come to light recently. You could
substitute an sha1 hash instead of md5 hash if you wanted -- and if you have
libmcrypt or something.
Let me know what you think or if you find any flaws in this.
Dean.