Re: Re: WAYS OF AUTHENICATION - open discussion

From: Date: Sun, 05 Nov 2000 21:19:57 +0000
Subject: Re: Re: WAYS OF AUTHENICATION - open discussion
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-23812@lists.php.net to get a copy of this message
Almost forgot: You can see this in action at <http://www.apt7.com/index.php?id1=login>. You can't log in, of course, but you can view the HTML source. :-) Dean. ----- Original Message ----- From: "Dean Hall" <hall@apt7.com> To: <php-general@lists.php.net> Sent: Sunday, November 05, 2000 3:17 PM Subject: Re: [PHP] Re: WAYS OF AUTHENICATION - open discussion > I thought I'd put in my $0.02-worth on user authentication and share the > method I use on my website. > > First, I store all user's passwords as md5-hashed strings in a mysql > database. (I of course store usernames in the same table as the primary > key.) > > My login page has a JavaScript source file that implements the md5 hash. > (You can find it at <http://www.apt7.com/js/md5.js> and > its web-viewable > version at <http://www.apt7.com/js/md5.txt>.) > > My login form has a hidden form element called 'timestamp', which is, > obviously, the string version of a Unix timestamp, and a hidden form element > called 'login_hash'. The submit button for the form calls a JavaScript > function called 'submit_form', which does the following: It does an md5 hash > on the password. It concatenates the hashed password with the 'timestamp' > and does an md5 hash on this string and assigns it to 'login_hash'. Then it > sets the password form element of the form to "", and submits the form. > Here's a little mock-up of the whole thing: > > // begin login.php > > <?php > $time = time(); > ?> > <script language="JavaScript" src="md5.js"> > </script> > <script language="JavaScript"> > <!-- // > function submit_login() { > // do some form validation here > passhash = MD5(document.login.password.value); > document.login.password.value = ""; > passhash = MD5(passhash . document.login.timestamp.value); > document.login.login_hash.value = passhash; > document.login.submit(); > return true; > } > // --> > </script> > > <form name="login" method="login_handler.php" > action="POST"> > <input type="hidden" name="timestamp" value="<?php echo > $time;?>"> > <input type="hidden" name="login_hash" value=""> > Username: <input type="text" name="username" > value=""><br> > Password: <input type="password" name="password" > value=""><br> > <input type="submit" value="Log in" onClick="submit_login(); return false;"> > </form> > > // end login.php > // begin login_handler.php > > <? > $username = $HTTP_POST_VARS[username]; > $login_hash = $HTTP_POST_VARS[login_hash]; > $timestamp = $HTTP_POST_VARS[timestamp]; > > $real_pass_hash = // do database query to get the md5-hashed password from > DB > $real_login_hash = md5($real_pass_hash . $timestamp); > if(strcmp($real_login_hash, $login_hash) == 0) { > // authenticate the user > } > else { > // don't authenticate the user > } > > // end login_handler.php > > Now this takes care of several things: > > First, the user's password is not sent in plaintext. > > Second, the password hash that is sent is unique every time the user logs > in. > > The only problem with this that I can see is the inherent flaw in the md5 > cryptographic hash function that has come to light recently. You could > substitute an sha1 hash instead of md5 hash if you wanted -- and if you have > libmcrypt or something. > > Let me know what you think or if you find any flaws in this. > > Dean. > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#23812) next »