PHP And System Passwords

From: Date: Fri, 17 Nov 2000 22:24:16 +0000
Subject: PHP And System Passwords
Groups: php.general 
Request: Send a blank email to php-general+get-25968@lists.php.net to get a copy of this message
I appear to have had a mistaken assumption about PHP authentication and passwords. This was my assumption: Causing a username/password dialog box to pop up by using code such as this: if (!isset($PHP_AUTH_USER)) { # send header that creates dialog box header('WWW-Authenticate:Basic realm="MyDomain"'); header('HTTP/1.0 401 Unauthorized'); echo ' Error message here'; die(); }; $username = $PHP_AUTH_USER; checks the system password for authentication. I could have sworn that I tested this and that, if a username is entered correctly but a password is entered incorrectly, the dialog box simply pops up again. If the user enters their password incorrectly three times, the error message shows. It appears that I was wrong. It appears that ANY password entered, as long as a valid username is entered, will make the user gain access to the system. Has this been found to be true in your experience? If not, what are you doing differently? Also, am I going to have to resort to a crypt() routine to check passwords? (Yes, I know crypt() can be insecure, but at this point I cannot make a database of usernames and passwords. Also, a database full of passwords has inherent security issues as well.) I would appreciate some feedback. Erica

« previous php.general (#25968) next »