Re: Re: WAYS OF AUTHENICATION - open discussion
| From: | scottrus at ipass dot net | Date: | Mon, 06 Nov 2000 15:18:57 +0000 |
| Subject: | Re: Re: WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 2 3 4 5 6 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23885@lists.php.net to get a copy of this message | ||
Having a user swipe a page and alter the cgi input is a problem for any
input, not just auth.
I have this small bit of code in an auto append file. This should be
executed before any HTML headers go out.
<?
global $HTTP_POST_VARS, $HTTP_SERVER_VARS;
if (!empty($HTTP_POST_VARS) &
!strstr($HTTP_SERVER_VARS["HTTP_REFERER"],$HTTP_SERVER_VARS["HTTP_HOST"])) {
header("Location: /error_docs/badcgi.html");
exit;
}
?>
This code bit first checks to see if post data was sent and if so that the
contents of HTTP_REFERER are in the HTTP_HOST var. If they're not then this post
came from another site and it should be rejected.
I don't cover get methods 'cause I want people to be able to bookmark get method
docs without a hassle. As a result I don't take free from inputs using get and tend to
limit get method input to simple numeric args to make bounds checking easier.
Also, regarding user auth, I think the best way is to use basic browser authentication
through php. It's a bit more complex to write in some cases but it helps eliminate
people swiping the login form and trying to hack it to by pass the auth check.
Hope it helps.
-- Scott
On Sun, Nov 05, 2000 at 10:02:18PM -0600, Dean Hall wrote:
>
> As Manuel aptly put it, there seems to be nothing to prevent someone from
> swiping the same page and submitting the exact same values as a valid user
> did. In my case, I use a timestamp that's hashed into the password. When a
> minute has passed according to this timestamp, the whole page becomes
> invalid and a login is not allowed. I don't see how your scheme prevents
> such a thing from happening.
>
> Dean.
--
Scott