Re: Re: WAYS OF AUTHENICATION - open discussion
| From: | Dean Hall | Date: | Mon, 06 Nov 2000 22:43:23 +0000 |
| Subject: | Re: Re: WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23995@lists.php.net to get a copy of this message | ||
Please read the original post. Making a random server-side variable does me
no good if the user submits the password in plain text.
Dean.
----- Original Message -----
From: "Fábio Ottolini" <fabio.ottolini@uol.com.br>
To: <php-general@lists.php.net>
Sent: Monday, November 06, 2000 3:55 PM
Subject: Re: [PHP] Re: WAYS OF AUTHENICATION - open discussion
> You can do this without Javascript:
> <?php
> srand((double)microtime()*1000000);
> $session_id=md5(uniqid(rand()));
> ?>
>
> Best regards,
>
> Fábio Ottolini
> Eletronic.Net
>
> ----- Original Message -----
> From: "Dean Hall" <hall@apt7.com>
> To: <php-general@lists.php.net>
> Sent: Sunday, November 05, 2000 7:17 PM
> Subject: Re: [PHP] Re: WAYS OF AUTHENICATION - open discussion
>
>
> (...)
>
> > First, I store all user's passwords as md5-hashed strings in a mysql
> > database. (I of course store usernames in the same table as the primary
> > key.)
> >
> > My login page has a JavaScript source file that implements the md5 hash.
> > (You can find it at <http://www.apt7.com/js/md5.js>
> > and its web-viewable
> > version at <http://www.apt7.com/js/md5.txt>.)
>
> (...)
>
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net