Re: Re: WAYS OF AUTHENICATION - open discussion
| From: | Dean Hall | Date: | Sun, 05 Nov 2000 21:19:57 +0000 |
| Subject: | Re: Re: WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23812@lists.php.net to get a copy of this message | ||
Almost forgot:
You can see this in action at <http://www.apt7.com/index.php?id1=login>. You
can't log in, of course, but you can view the HTML source. :-)
Dean.
----- Original Message -----
From: "Dean Hall" <hall@apt7.com>
To: <php-general@lists.php.net>
Sent: Sunday, November 05, 2000 3:17 PM
Subject: Re: [PHP] Re: WAYS OF AUTHENICATION - open discussion
> I thought I'd put in my $0.02-worth on user authentication and share the
> method I use on my website.
>
> First, I store all user's passwords as md5-hashed strings in a mysql
> database. (I of course store usernames in the same table as the primary
> key.)
>
> My login page has a JavaScript source file that implements the md5 hash.
> (You can find it at <http://www.apt7.com/js/md5.js> and
> its web-viewable
> version at <http://www.apt7.com/js/md5.txt>.)
>
> My login form has a hidden form element called 'timestamp', which is,
> obviously, the string version of a Unix timestamp, and a hidden form
element
> called 'login_hash'. The submit button for the form calls a JavaScript
> function called 'submit_form', which does the following: It does an md5
hash
> on the password. It concatenates the hashed password with the 'timestamp'
> and does an md5 hash on this string and assigns it to 'login_hash'. Then
it
> sets the password form element of the form to "", and submits the form.
> Here's a little mock-up of the whole thing:
>
> // begin login.php
>
> <?php
> $time = time();
> ?>
> <script language="JavaScript" src="md5.js">
> </script>
> <script language="JavaScript">
> <!-- //
> function submit_login() {
> // do some form validation here
> passhash = MD5(document.login.password.value);
> document.login.password.value = "";
> passhash = MD5(passhash . document.login.timestamp.value);
> document.login.login_hash.value = passhash;
> document.login.submit();
> return true;
> }
> // -->
> </script>
>
> <form name="login" method="login_handler.php"
> action="POST">
> <input type="hidden" name="timestamp" value="<?php echo
> $time;?>">
> <input type="hidden" name="login_hash" value="">
> Username: <input type="text" name="username"
> value=""><br>
> Password: <input type="password" name="password"
> value=""><br>
> <input type="submit" value="Log in" onClick="submit_login(); return
false;">
> </form>
>
> // end login.php
> // begin login_handler.php
>
> <?
> $username = $HTTP_POST_VARS[username];
> $login_hash = $HTTP_POST_VARS[login_hash];
> $timestamp = $HTTP_POST_VARS[timestamp];
>
> $real_pass_hash = // do database query to get the md5-hashed password from
> DB
> $real_login_hash = md5($real_pass_hash . $timestamp);
> if(strcmp($real_login_hash, $login_hash) == 0) {
> // authenticate the user
> }
> else {
> // don't authenticate the user
> }
>
> // end login_handler.php
>
> Now this takes care of several things:
>
> First, the user's password is not sent in plaintext.
>
> Second, the password hash that is sent is unique every time the user logs
> in.
>
> The only problem with this that I can see is the inherent flaw in the md5
> cryptographic hash function that has come to light recently. You could
> substitute an sha1 hash instead of md5 hash if you wanted -- and if you
have
> libmcrypt or something.
>
> Let me know what you think or if you find any flaws in this.
>
> Dean.
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net