Re: Re: WAYS OF AUTHENICATION - open discussion

From: Date: Mon, 06 Nov 2000 04:36:27 +0000
Subject: Re: Re: WAYS OF AUTHENICATION - open discussion
References: 1 2 3 4 5 6 7  Groups: php.general 
Request: Send a blank email to php-general+get-23841@lists.php.net to get a copy of this message
> > > I would be very interested and grateful if anyone can help me poke holes > > in > > > this method. > > > > > > Joe > > > > As Manuel aptly put it, there seems to be nothing to prevent someone from > > swiping the same page and submitting the exact same values as a valid user > > did. In my case, I use a timestamp that's hashed into the password. When a > > minute has passed according to this timestamp, the whole page becomes > > invalid and a login is not allowed. I don't see how your scheme prevents > > such a thing from happening. > > > > Dean. > > Since the token is maintained in a session variable *and* in the page, if > someone else submits the exact same page the two tokens will be different > and therefore the login will fail. At least I can't think of a way unless > someone can hijack a live session from someone else. Is that possible? > > Joe > > Here's a snippet of the code: > <snip> > Forgot to mention that the $token and $loggedin variables are registered in an include file that doesn't show up in the snippet that I sent. Joe

« previous php.general (#23841) next »