Re: Re: WAYS OF AUTHENICATION - open discussion

From: Date: Mon, 06 Nov 2000 18:14:24 +0000
Subject: Re: Re: WAYS OF AUTHENICATION - open discussion
References: 1 2 3 4  Groups: php.general 
Request: Send a blank email to php-general+get-23941@lists.php.net to get a copy of this message
=== Dean Hall escribia (Sun, Nov 05, 2000 at 09:07:37PM -0600): > [My original post omitted.] > > I'd say this method is severely flawed, if I understand > > correctly. Indeed the password is not sent in plain text, but if > > I can listen to the session then the md5 hash and the timestamp > > is all I need. What prevents me from fabricating my own form and > > reuse in it both the md5 hash and the timestamp ? > > > > Manuel Garcia > > Okay, one thing I forgot to mention is that there is a time limit of one > minute on how long the user can take to log in. If there was no such time > limit, you would be correct. With this time limit, if someone can listen in > and get the hash in that time span, yes, you can. Aha ... and I don't think it's too difficult to do so. The whole attack can be automated. Manuel Garcia

« previous php.general (#23941) next »