Re: Re: WAYS OF AUTHENICATION - open discussion

From: Date: Mon, 06 Nov 2000 15:18:57 +0000
Subject: Re: Re: WAYS OF AUTHENICATION - open discussion
References: 1 2 3 4 5 6  Groups: php.general 
Request: Send a blank email to php-general+get-23885@lists.php.net to get a copy of this message
Having a user swipe a page and alter the cgi input is a problem for any input, not just auth. I have this small bit of code in an auto append file. This should be executed before any HTML headers go out. <? global $HTTP_POST_VARS, $HTTP_SERVER_VARS; if (!empty($HTTP_POST_VARS) & !strstr($HTTP_SERVER_VARS["HTTP_REFERER"],$HTTP_SERVER_VARS["HTTP_HOST"])) { header("Location: /error_docs/badcgi.html"); exit; } ?> This code bit first checks to see if post data was sent and if so that the contents of HTTP_REFERER are in the HTTP_HOST var. If they're not then this post came from another site and it should be rejected. I don't cover get methods 'cause I want people to be able to bookmark get method docs without a hassle. As a result I don't take free from inputs using get and tend to limit get method input to simple numeric args to make bounds checking easier. Also, regarding user auth, I think the best way is to use basic browser authentication through php. It's a bit more complex to write in some cases but it helps eliminate people swiping the login form and trying to hack it to by pass the auth check. Hope it helps. -- Scott On Sun, Nov 05, 2000 at 10:02:18PM -0600, Dean Hall wrote: > > As Manuel aptly put it, there seems to be nothing to prevent someone from > swiping the same page and submitting the exact same values as a valid user > did. In my case, I use a timestamp that's hashed into the password. When a > minute has passed according to this timestamp, the whole page becomes > invalid and a login is not allowed. I don't see how your scheme prevents > such a thing from happening. > > Dean. -- Scott

« previous php.general (#23885) next »