PHP And System Passwords
| From: | Erica Douglass | Date: | Fri, 17 Nov 2000 22:24:16 +0000 |
| Subject: | PHP And System Passwords | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-25968@lists.php.net to get a copy of this message | ||
I appear to have had a mistaken assumption about PHP authentication and
passwords.
This was my assumption:
Causing a username/password dialog box to pop up by using code such as this:
if (!isset($PHP_AUTH_USER))
{
# send header that creates dialog box
header('WWW-Authenticate:Basic realm="MyDomain"');
header('HTTP/1.0 401 Unauthorized');
echo ' Error message here';
die();
};
$username = $PHP_AUTH_USER;
checks the system password for authentication.
I could have sworn that I tested this and that, if a username is entered
correctly but a password is entered incorrectly, the dialog box simply pops
up again. If the user enters their password incorrectly three times, the
error message shows. It appears that I was wrong. It appears that ANY
password entered, as long as a valid username is entered, will make the user
gain access to the system.
Has this been found to be true in your experience? If not, what are you
doing differently? Also, am I going to have to resort to a crypt() routine
to check passwords? (Yes, I know crypt() can be insecure, but at this point
I cannot make a database of usernames and passwords. Also, a database full
of passwords has inherent security issues as well.)
I would appreciate some feedback.
Erica