SECURE USERNAME IDENTIFICATION
| From: | Ihr WEBberater | Date: | Tue, 07 Nov 2000 20:08:25 +0000 |
| Subject: | SECURE USERNAME IDENTIFICATION | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-24175@lists.php.net to get a copy of this message | ||
I set a cookie when a visitor has logged in with a valid
usern & passwort variable - and all forms a filled
with the according variables. (street, zip-code etc...)
what about a hacker trying to force by pages
to think there's a valid user by typing
like: http://www.wa-p.de/user_page.php4?usern=XXXXX
By testing this link for several times, the hacker
could be lucky!
I only what my authentification-page to set a cookie
which says that a user is valid!
+++++++++++++++++++++++++++++++++++++++++++++++++++
+ Ihr WEBberater Tel. 07161 - 92 95 94 +
+ Stuttgarter Str. 3 Fax 07161 - 92 95 98 +
+ D-73033 Göppingen +
+++++++++++++++++++++++++++++++++++++++++++++++++++
+ Internet: www.wa-p.de +
+ eMail: info@wa-p.de +
+ Anfrage: anfrage@wa-p.de +
+ Support: support@wa-p.de +
+++++++++++++++++++++++++++++++++++++++++++++++++++