Re: PHP And System Passwords
| From: | Ignacio Vazquez-Abrams | Date: | Fri, 17 Nov 2000 22:32:57 +0000 |
| Subject: | Re: PHP And System Passwords | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-25969@lists.php.net to get a copy of this message | ||
On Fri, 17 Nov 2000, Erica Douglass wrote:
> I appear to have had a mistaken assumption about PHP authentication and
> passwords.
>
> This was my assumption:
>
> Causing a username/password dialog box to pop up by using code such as this:
>
> if (!isset($PHP_AUTH_USER))
> {
> # send header that creates dialog box
> header('WWW-Authenticate:Basic realm="MyDomain"');
> header('HTTP/1.0 401 Unauthorized');
> echo ' Error message here';
> die();
> };
> $username = $PHP_AUTH_USER;
>
> checks the system password for authentication.
>
> I could have sworn that I tested this and that, if a username is entered
> correctly but a password is entered incorrectly, the dialog box simply pops
> up again. If the user enters their password incorrectly three times, the
> error message shows. It appears that I was wrong. It appears that ANY
> password entered, as long as a valid username is entered, will make the user
> gain access to the system.
>
> Has this been found to be true in your experience? If not, what are you
> doing differently? Also, am I going to have to resort to a crypt() routine
> to check passwords? (Yes, I know crypt() can be insecure, but at this point
> I cannot make a database of usernames and passwords. Also, a database full
> of passwords has inherent security issues as well.)
>
> I would appreciate some feedback.
>
> Erica
>
Actually, all your code does is make the browser ask the user for a userid
and password; it doesn't actually check the password. To do that, you have
to make sure that the returned plaintext password is correct.
You don't have to use crypt() to store your passwords, but some sort of
hashing (i.e., crypt() or md5()) is highly recommended.
--
Ignacio Vazquez-Abrams <ignacio@openservices.net>