Re: Re: WAYS OF AUTHENICATION - open discussion

From: Date: Mon, 06 Nov 2000 21:46:30 +0000
Subject: Re: Re: WAYS OF AUTHENICATION - open discussion
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-23985@lists.php.net to get a copy of this message
The thing is that if you have lots of users things can get very tricky... At least one line per user. If a user wants to change the password how are you goint to handle the change? That's why I believe DB's are more suitable for this situation. Security is not the big issue in this case unless you have your document_root set as "/" (just kidding). On the other hand, supposing a crazy and lunatic web admin messes up with Apache's conf files removing PHP MIME types and PHP files are sent to the browser just as plain text, passwords are going to be read by anyone who tries to get a hold of your include file!!! Best regards, Fábio Ottolini Eletronic.Net ----- Original Message ----- From: "Richard Creech - DreamRiver.com" <richardc@dreamriver.com> To: <php-general@lists.php.net> Sent: Sunday, November 05, 2000 6:49 PM Subject: [PHP] Re: WAYS OF AUTHENICATION - open discussion > Hello, > I have a question about a third 'authentication' method I haven't seen discussed in this thread. The method is hand rolled username / password combination using constants protected by a transparent parsed include file like this: > > <?php include("util.php3"); ?> > > ... util.php3 contains this code: > > define("ADMINHOME", "admin.php3"); > define("ADMINUSER", "EnterAnAdminUserNameHere"); > > util.php3 is INSIDE the publicly accessible web tree ( a basedir restriction is in effect preventing me from putting the file somewhere safer ) > > The files (just a few) are protected using this method by the conditional execution of a page like this: > > <?php > if (($formuser != ADMINUSER) || ($formpassword != ADMINPASSWORD)){ > echo "<p class='accessdenied'>Access<br>denied.</p>"; > exit; > }else{ > // user is allowed in... > > My question for this list is what are the potential security risks with this method and how can they be minimized? > > Kind Regards, > > Richard Creech

« previous php.general (#23985) next »