Re: PHP And System Passwords

From: Date: Fri, 17 Nov 2000 22:32:57 +0000
Subject: Re: PHP And System Passwords
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-25969@lists.php.net to get a copy of this message
On Fri, 17 Nov 2000, Erica Douglass wrote: > I appear to have had a mistaken assumption about PHP authentication and > passwords. > > This was my assumption: > > Causing a username/password dialog box to pop up by using code such as this: > > if (!isset($PHP_AUTH_USER)) > { > # send header that creates dialog box > header('WWW-Authenticate:Basic realm="MyDomain"'); > header('HTTP/1.0 401 Unauthorized'); > echo ' Error message here'; > die(); > }; > $username = $PHP_AUTH_USER; > > checks the system password for authentication. > > I could have sworn that I tested this and that, if a username is entered > correctly but a password is entered incorrectly, the dialog box simply pops > up again. If the user enters their password incorrectly three times, the > error message shows. It appears that I was wrong. It appears that ANY > password entered, as long as a valid username is entered, will make the user > gain access to the system. > > Has this been found to be true in your experience? If not, what are you > doing differently? Also, am I going to have to resort to a crypt() routine > to check passwords? (Yes, I know crypt() can be insecure, but at this point > I cannot make a database of usernames and passwords. Also, a database full > of passwords has inherent security issues as well.) > > I would appreciate some feedback. > > Erica > Actually, all your code does is make the browser ask the user for a userid and password; it doesn't actually check the password. To do that, you have to make sure that the returned plaintext password is correct. You don't have to use crypt() to store your passwords, but some sort of hashing (i.e., crypt() or md5()) is highly recommended. -- Ignacio Vazquez-Abrams <ignacio@openservices.net>

« previous php.general (#25969) next »