Re: Re: WAYS OF AUTHENICATION - open discussion

From: Date: Sun, 05 Nov 2000 21:37:54 +0000
Subject: Re: Re: WAYS OF AUTHENICATION - open discussion
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-23823@lists.php.net to get a copy of this message
=== Dean Hall escribia (Sun, Nov 05, 2000 at 03:17:32PM -0600): > I thought I'd put in my $0.02-worth on user authentication and share the > method I use on my website. > > First, I store all user's passwords as md5-hashed strings in a mysql > database. (I of course store usernames in the same table as the primary > key.) > > My login page has a JavaScript source file that implements the md5 hash. > (You can find it at <http://www.apt7.com/js/md5.js> and > its web-viewable > version at <http://www.apt7.com/js/md5.txt>.) > > My login form has a hidden form element called 'timestamp', which is, > obviously, the string version of a Unix timestamp, and a hidden form element > called 'login_hash'. The submit button for the form calls a JavaScript > function called 'submit_form', which does the following: It does an md5 hash > on the password. It concatenates the hashed password with the 'timestamp' > and does an md5 hash on this string and assigns it to 'login_hash'. Then it > sets the password form element of the form to "", and submits the form. > Here's a little mock-up of the whole thing: > > // begin login.php > > <?php > $time = time(); > ?> > <script language="JavaScript" src="md5.js"> > </script> > <script language="JavaScript"> > <!-- // > function submit_login() { > // do some form validation here > passhash = MD5(document.login.password.value); > document.login.password.value = ""; > passhash = MD5(passhash . document.login.timestamp.value); > document.login.login_hash.value = passhash; > document.login.submit(); > return true; > } > // --> > </script> > > <form name="login" method="login_handler.php" > action="POST"> > <input type="hidden" name="timestamp" value="<?php echo > $time;?>"> > <input type="hidden" name="login_hash" value=""> > Username: <input type="text" name="username" > value=""><br> > Password: <input type="password" name="password" > value=""><br> > <input type="submit" value="Log in" onClick="submit_login(); return > false;"> > </form> > > // end login.php > // begin login_handler.php > > <? > $username = $HTTP_POST_VARS[username]; > $login_hash = $HTTP_POST_VARS[login_hash]; > $timestamp = $HTTP_POST_VARS[timestamp]; > > $real_pass_hash = // do database query to get the md5-hashed password from > DB > $real_login_hash = md5($real_pass_hash . $timestamp); > if(strcmp($real_login_hash, $login_hash) == 0) { > // authenticate the user > } > else { > // don't authenticate the user > } > > // end login_handler.php > > Now this takes care of several things: > > First, the user's password is not sent in plaintext. > > Second, the password hash that is sent is unique every time the user logs > in. > > The only problem with this that I can see is the inherent flaw in the md5 > cryptographic hash function that has come to light recently. You could > substitute an sha1 hash instead of md5 hash if you wanted -- and if you have > libmcrypt or something. > > Let me know what you think or if you find any flaws in this. I'd say this method is severely flawed, if I understand correctly. Indeed the password is not sent in plain text, but if I can listen to the session then the md5 hash and the timestamp is all I need. What prevents me from fabricating my own form and reuse in it both the md5 hash and the timestamp ? > > Dean. Manuel Garcia

« previous php.general (#23823) next »