Re: Re: WAYS OF AUTHENICATION - open discussion
| From: | Joe Conway | Date: | Mon, 06 Nov 2000 04:30:56 +0000 |
| Subject: | Re: Re: WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 2 3 4 5 6 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23840@lists.php.net to get a copy of this message | ||
> >
> > I would be very interested and grateful if anyone can help me poke holes
> in
> > this method.
> >
> > Joe
>
> As Manuel aptly put it, there seems to be nothing to prevent someone from
> swiping the same page and submitting the exact same values as a valid user
> did. In my case, I use a timestamp that's hashed into the password. When a
> minute has passed according to this timestamp, the whole page becomes
> invalid and a login is not allowed. I don't see how your scheme prevents
> such a thing from happening.
>
> Dean.
Since the token is maintained in a session variable *and* in the page, if
someone else submits the exact same page the two tokens will be different
and therefore the login will fail. At least I can't think of a way unless
someone can hijack a live session from someone else. Is that possible?
Joe
Here's a snippet of the code:
<snip>
<?PHP
if (! isset($loggedin)) {
$loggedin = false;
};
if (isset($HTTP_POST_VARS["auth_token"])) {
$sql = "select password from tbl_admin where loginname = '" .
$HTTP_POST_VARS["loginname"] . "'";
$rs = connexec($conn,$sql);
$rsf = rsfetchrs($rs);
$dblookup_password = $rsf[0]["password"];
$auth_token = md5($token . $dblookup_password);
if ($HTTP_POST_VARS["auth_token"] === $auth_token) {
$loggedin = true;
}
}
if (! $loggedin) {
mt_srand((double)microtime()*1000000);
$token = uniqid (mt_rand()) . $HTTP_SERVER_VARS["REMOTE_ADDR"];
echo "
<SCRIPT language=JavaScript src='md5.js'></SCRIPT>
<SCRIPT language=JavaScript>
<!--
function fn_login() {
var md5pwd;
lForm = window.document.loginform;
md5pwd = MD5(lForm.password.value);
lForm.password.value = '';
lForm.auth_token.value = MD5('$token' + md5pwd);
lForm.submit();
}
//-->
</SCRIPT>
";
echo "
<!-- ****************** BEGIN LOGIN FORM ******************-->
. . . login form stuff . . .
</snip>