Re: Re: WAYS OF AUTHENICATION - open discussion
| From: | Manuel Enrique Garcia Cuesta | Date: | Mon, 06 Nov 2000 18:14:24 +0000 |
| Subject: | Re: Re: WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 2 3 4 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23941@lists.php.net to get a copy of this message | ||
=== Dean Hall escribia
(Sun, Nov 05, 2000 at 09:07:37PM -0600):
> [My original post omitted.]
> > I'd say this method is severely flawed, if I understand
> > correctly. Indeed the password is not sent in plain text, but if
> > I can listen to the session then the md5 hash and the timestamp
> > is all I need. What prevents me from fabricating my own form and
> > reuse in it both the md5 hash and the timestamp ?
> >
> > Manuel Garcia
>
> Okay, one thing I forgot to mention is that there is a time limit of one
> minute on how long the user can take to log in. If there was no such time
> limit, you would be correct. With this time limit, if someone can listen in
> and get the hash in that time span, yes, you can.
Aha ... and I don't think it's too difficult to do so. The whole
attack can be automated.
Manuel Garcia