Re: Re: WAYS OF AUTHENICATION - open discussion

From: Date: Mon, 06 Nov 2000 03:07:37 +0000
Subject: Re: Re: WAYS OF AUTHENICATION - open discussion
References: 1 2 3  Groups: php.general 
Request: Send a blank email to php-general+get-23831@lists.php.net to get a copy of this message
[My original post omitted.] > I'd say this method is severely flawed, if I understand > correctly. Indeed the password is not sent in plain text, but if > I can listen to the session then the md5 hash and the timestamp > is all I need. What prevents me from fabricating my own form and > reuse in it both the md5 hash and the timestamp ? > > Manuel Garcia Okay, one thing I forgot to mention is that there is a time limit of one minute on how long the user can take to log in. If there was no such time limit, you would be correct. With this time limit, if someone can listen in and get the hash in that time span, yes, you can. So, when the user logs in, the first thing I check is whether one minute has expired since the timestamp occurred. If so, the user has to try again. If not, I allow the login. Anything else? Dean.

« previous php.general (#23831) next »