Re: Re: WAYS OF AUTHENICATION - open discussion
| From: | Manuel Enrique Garcia Cuesta | Date: | Sun, 05 Nov 2000 21:37:54 +0000 |
| Subject: | Re: Re: WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23823@lists.php.net to get a copy of this message | ||
=== Dean Hall escribia
(Sun, Nov 05, 2000 at 03:17:32PM -0600):
> I thought I'd put in my $0.02-worth on user authentication and share the
> method I use on my website.
>
> First, I store all user's passwords as md5-hashed strings in a mysql
> database. (I of course store usernames in the same table as the primary
> key.)
>
> My login page has a JavaScript source file that implements the md5 hash.
> (You can find it at <http://www.apt7.com/js/md5.js> and
> its web-viewable
> version at <http://www.apt7.com/js/md5.txt>.)
>
> My login form has a hidden form element called 'timestamp', which is,
> obviously, the string version of a Unix timestamp, and a hidden form element
> called 'login_hash'. The submit button for the form calls a JavaScript
> function called 'submit_form', which does the following: It does an md5 hash
> on the password. It concatenates the hashed password with the 'timestamp'
> and does an md5 hash on this string and assigns it to 'login_hash'. Then it
> sets the password form element of the form to "", and submits the form.
> Here's a little mock-up of the whole thing:
>
> // begin login.php
>
> <?php
> $time = time();
> ?>
> <script language="JavaScript" src="md5.js">
> </script>
> <script language="JavaScript">
> <!-- //
> function submit_login() {
> // do some form validation here
> passhash = MD5(document.login.password.value);
> document.login.password.value = "";
> passhash = MD5(passhash . document.login.timestamp.value);
> document.login.login_hash.value = passhash;
> document.login.submit();
> return true;
> }
> // -->
> </script>
>
> <form name="login" method="login_handler.php"
> action="POST">
> <input type="hidden" name="timestamp" value="<?php echo
> $time;?>">
> <input type="hidden" name="login_hash" value="">
> Username: <input type="text" name="username"
> value=""><br>
> Password: <input type="password" name="password"
> value=""><br>
> <input type="submit" value="Log in" onClick="submit_login(); return
> false;">
> </form>
>
> // end login.php
> // begin login_handler.php
>
> <?
> $username = $HTTP_POST_VARS[username];
> $login_hash = $HTTP_POST_VARS[login_hash];
> $timestamp = $HTTP_POST_VARS[timestamp];
>
> $real_pass_hash = // do database query to get the md5-hashed password from
> DB
> $real_login_hash = md5($real_pass_hash . $timestamp);
> if(strcmp($real_login_hash, $login_hash) == 0) {
> // authenticate the user
> }
> else {
> // don't authenticate the user
> }
>
> // end login_handler.php
>
> Now this takes care of several things:
>
> First, the user's password is not sent in plaintext.
>
> Second, the password hash that is sent is unique every time the user logs
> in.
>
> The only problem with this that I can see is the inherent flaw in the md5
> cryptographic hash function that has come to light recently. You could
> substitute an sha1 hash instead of md5 hash if you wanted -- and if you have
> libmcrypt or something.
>
> Let me know what you think or if you find any flaws in this.
I'd say this method is severely flawed, if I understand
correctly. Indeed the password is not sent in plain text, but if
I can listen to the session then the md5 hash and the timestamp
is all I need. What prevents me from fabricating my own form and
reuse in it both the md5 hash and the timestamp ?
>
> Dean.
Manuel Garcia