Re: Re: WAYS OF AUTHENICATION - open discussion
| From: | Manuel Enrique Garcia Cuesta | Date: | Mon, 06 Nov 2000 18:45:40 +0000 |
| Subject: | Re: Re: WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23961@lists.php.net to get a copy of this message | ||
=== Joe Conway escribia
(Sun, Nov 05, 2000 at 08:30:56PM -0800):
> Since the token is maintained in a session variable *and* in the page, if
> someone else submits the exact same page the two tokens will be different
> and therefore the login will fail. At least I can't think of a way unless
> someone can hijack a live session from someone else. Is that possible?
But the auth_token var and everything are still visible,
and (I believe ) nothing prevents you from triggering the very
same session the legal user is engaged in. Even if you destroy the
$token variable immediately after the user successfuly logs in you
cannot guarantee that it was the legal user who did so.
>
> Joe
Manuel Garcia
>
> Here's a snippet of the code:
> <snip>
>
> <?PHP
> if (! isset($loggedin)) {
> $loggedin = false;
> };
> if (isset($HTTP_POST_VARS["auth_token"])) {
> $sql = "select password from tbl_admin where loginname = '" .
> $HTTP_POST_VARS["loginname"] . "'";
> $rs = connexec($conn,$sql);
> $rsf = rsfetchrs($rs);
> $dblookup_password = $rsf[0]["password"];
> $auth_token = md5($token . $dblookup_password);
> if ($HTTP_POST_VARS["auth_token"] === $auth_token) {
> $loggedin = true;
> }
> }
> if (! $loggedin) {
> mt_srand((double)microtime()*1000000);
> $token = uniqid (mt_rand()) . $HTTP_SERVER_VARS["REMOTE_ADDR"];
> echo "
> <SCRIPT language=JavaScript src='md5.js'></SCRIPT>
> <SCRIPT language=JavaScript>
> <!--
> function fn_login() {
> var md5pwd;
> lForm = window.document.loginform;
> md5pwd = MD5(lForm.password.value);
> lForm.password.value = '';
> lForm.auth_token.value = MD5('$token' + md5pwd);
> lForm.submit();
> }
> //-->
> </SCRIPT>
> ";
> echo "
> <!-- ****************** BEGIN LOGIN FORM ******************-->
> . . . login form stuff . . .
>
> </snip>
>