Re: Re: WAYS OF AUTHENICATION - open discussion
| From: | F�bio Ottolini | Date: | Mon, 06 Nov 2000 21:46:30 +0000 |
| Subject: | Re: Re: WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23985@lists.php.net to get a copy of this message | ||
The thing is that if you have lots of users things can get very tricky... At
least one line per user. If a user wants to change the password how are you
goint to handle the change? That's why I believe DB's are more suitable for
this situation. Security is not the big issue in this case unless you have
your document_root set as "/" (just kidding). On the other hand, supposing a
crazy and lunatic web admin messes up with Apache's conf files removing PHP
MIME types and PHP files are sent to the browser just as plain text,
passwords are going to be read by anyone who tries to get a hold of your
include file!!!
Best regards,
Fábio Ottolini
Eletronic.Net
----- Original Message -----
From: "Richard Creech - DreamRiver.com" <richardc@dreamriver.com>
To: <php-general@lists.php.net>
Sent: Sunday, November 05, 2000 6:49 PM
Subject: [PHP] Re: WAYS OF AUTHENICATION - open discussion
> Hello,
> I have a question about a third 'authentication' method I haven't seen
discussed in this thread. The method is hand rolled username / password
combination using constants protected by a transparent parsed include file
like this:
>
> <?php include("util.php3"); ?>
>
> ... util.php3 contains this code:
>
> define("ADMINHOME", "admin.php3");
> define("ADMINUSER", "EnterAnAdminUserNameHere");
>
> util.php3 is INSIDE the publicly accessible web tree ( a basedir
restriction is in effect preventing me from putting the file somewhere
safer )
>
> The files (just a few) are protected using this method by the conditional
execution of a page like this:
>
> <?php
> if (($formuser != ADMINUSER) || ($formpassword != ADMINPASSWORD)){
> echo "<p class='accessdenied'>Access<br>denied.</p>";
> exit;
> }else{
> // user is allowed in...
>
> My question for this list is what are the potential security risks with
this method and how can they be minimized?
>
> Kind Regards,
>
> Richard Creech