Re: Re: WAYS OF AUTHENICATION - open discussion
| From: | Joe Conway | Date: | Mon, 06 Nov 2000 04:36:27 +0000 |
| Subject: | Re: Re: WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23841@lists.php.net to get a copy of this message | ||
> > > I would be very interested and grateful if anyone can help me poke
holes
> > in
> > > this method.
> > >
> > > Joe
> >
> > As Manuel aptly put it, there seems to be nothing to prevent someone
from
> > swiping the same page and submitting the exact same values as a valid
user
> > did. In my case, I use a timestamp that's hashed into the password. When
a
> > minute has passed according to this timestamp, the whole page becomes
> > invalid and a login is not allowed. I don't see how your scheme prevents
> > such a thing from happening.
> >
> > Dean.
>
> Since the token is maintained in a session variable *and* in the page, if
> someone else submits the exact same page the two tokens will be different
> and therefore the login will fail. At least I can't think of a way unless
> someone can hijack a live session from someone else. Is that possible?
>
> Joe
>
> Here's a snippet of the code:
> <snip>
>
Forgot to mention that the $token and $loggedin variables are registered in
an include file that doesn't show up in the snippet that I sent.
Joe