Re: Re: WAYS OF AUTHENICATION - open discussion

From: Date: Mon, 06 Nov 2000 04:30:56 +0000
Subject: Re: Re: WAYS OF AUTHENICATION - open discussion
References: 1 2 3 4 5 6  Groups: php.general 
Request: Send a blank email to php-general+get-23840@lists.php.net to get a copy of this message
> > > > I would be very interested and grateful if anyone can help me poke holes > in > > this method. > > > > Joe > > As Manuel aptly put it, there seems to be nothing to prevent someone from > swiping the same page and submitting the exact same values as a valid user > did. In my case, I use a timestamp that's hashed into the password. When a > minute has passed according to this timestamp, the whole page becomes > invalid and a login is not allowed. I don't see how your scheme prevents > such a thing from happening. > > Dean. Since the token is maintained in a session variable *and* in the page, if someone else submits the exact same page the two tokens will be different and therefore the login will fail. At least I can't think of a way unless someone can hijack a live session from someone else. Is that possible? Joe Here's a snippet of the code: <snip> <?PHP if (! isset($loggedin)) { $loggedin = false; }; if (isset($HTTP_POST_VARS["auth_token"])) { $sql = "select password from tbl_admin where loginname = '" . $HTTP_POST_VARS["loginname"] . "'"; $rs = connexec($conn,$sql); $rsf = rsfetchrs($rs); $dblookup_password = $rsf[0]["password"]; $auth_token = md5($token . $dblookup_password); if ($HTTP_POST_VARS["auth_token"] === $auth_token) { $loggedin = true; } } if (! $loggedin) { mt_srand((double)microtime()*1000000); $token = uniqid (mt_rand()) . $HTTP_SERVER_VARS["REMOTE_ADDR"]; echo " <SCRIPT language=JavaScript src='md5.js'></SCRIPT> <SCRIPT language=JavaScript> <!-- function fn_login() { var md5pwd; lForm = window.document.loginform; md5pwd = MD5(lForm.password.value); lForm.password.value = ''; lForm.auth_token.value = MD5('$token' + md5pwd); lForm.submit(); } //--> </SCRIPT> "; echo " <!-- ****************** BEGIN LOGIN FORM ******************--> . . . login form stuff . . . </snip>

« previous php.general (#23840) next »