RE: [PHP] Checking for cookies/session_existance.. very basic.

From: Date: Wed, 29 Nov 2000 20:42:39 +0000
Subject: RE: [PHP] Checking for cookies/session_existance.. very basic.
Groups: php.general 
Request: Send a blank email to php-general+get-27873@lists.php.net to get a copy of this message
Sending this out to the list for some more feedback.. The problem is I don't want to force a user to login to vote. If they have cookies enabled, it stores the pictures they voted on in a session variable, and they cannot vote until the next session. If they reject cookies, they can vote over and over and duplicate votes are not rejected. If I force cookies like you said, someone can write a perl/php shell script to automatically delete the cookie, and vote again. If I store the users IP, time, and picture ID in a table, that table would grow very large very fast, and the time it would take to do an SELECT than an INSERT on it would probably be adding too much overhead. Are there any other solutions, or is the table one the one I'm stuck with, perhaps combining that with a script to delete entries from the table older than 1 day, or something? (BTW -- the source code for the site I'm talking about will be open this week, I just got the project approved on SourceForge, so I hope people don't think I'm asking for help on something that they think I am profiting on, etc..) Thanks, Chad -----Original Message----- From: lee@server.mediawaveonline.com [mailto:lee@server.mediawaveonline.com] Sent: Wednesday, November 29, 2000 3:23 PM To: Chad Day Subject: RE: [PHP] Checking for cookies/session_existance.. very basic. I see perfect what your saying. That could defnitly be a problem. But even with cookies your still going to get the guy that has his cookies enabled, goes to the page, sets a cookie, votes, exit's his broser, deletes the cookie, and starts over with a new cookieID. For someone to write an simple script todo this with perl or php (shell scripting) would be very very easy. The only real way you can get around this is with a complicated username / password system. If there is no cookie as the user to login or sign-up, once a user has voted that username can't vote on that image anymore, if the user chooses to sign-up get email username email the user a temporary passwd, he can change it later. emailing the passwd to the customer will weed out fake email address, do not allow multiple email address's or usernames. ie if I signed up as lee@mediawaveonline.com username: lee do not alow me to sign up as either lee@mediawaveonline.com username: chris or wildmanele@hotmail.com username: lee This will weed out alot. Now the only way for someone to vote more then once is to have a shit load of email address's. This method isn't completely safe either. there are ways around this, but its not going to be easy. If someone set's up a mailserver on their computer, and set it so that any email, no matter the username goes to spec email address, ie. I have set up on our server that if the receipiet does not exist I forward the email to lostandfound@mediawaveonline.com, A person could set something up to desceive you, but this is more unlikely and alot harder then just loging out and re-entering your site. There are more ways too, log the users IP, maybe they are only alowd to vote once per 5min on an image with that IP, now the only way to get around this is to accually disconect from the internet and re-dialin just to vote again. there are problems with this too though, an perfect example is here in my office we have 10 computers behind a NAT router, all 10 computers have differnt IP's internally, but to the outside work they are all the same... I really hope this helps, please respond back so I know how this all worked out. Chris Lee Mediawaveonline.com On Wed, 29 Nov 2000, Chad Day wrote: > Hope you don't mind me mailing you privately. > > The site is xxx.xxx.xxx It starts up a session and when you > rate a picture, it throws that picture ID into an array that's session > registered and keeps track of what pictures you voted on, and wont let you > vote on them again until the session closes. If they reject the cookie, > they can vote and vote constantly. Someone did this to muck up the top 10 > lists and in general is being very annoying, so I'm trying to find a > workaround for it. > > phpinfo says my configure command was: > Configure command: './configure' '--with-mysql' > '--with-apache=../apache_1.3.12' '--enable-track-vars' > '--without-gd' > > Chad > > -----Original Message----- > From: Chris Lee [mailto:lee@mediawaveonline.com] > Sent: Tuesday, November 28, 2000 10:17 PM > To: php-general@lists.php.net > Subject: Re: [PHP] Checking for cookies/session_existance.. very basic. > > > You probably have --enable-trans-sid enabled when you compiled php, thus > when sessions are created they will first try cookies, if this fails it > will automaticaly try adding PHPSESSID= to all your links. > > if you ONLY want to use cookie's try the setcookie() command. > > http://www.php.net/manual/function.setcookie.php > > <? > if (!isset($done)) > { > $CookieID = time(); > $Exp = time() + 2592000 ; > setcookie("CookieID", $CookieID, $Exp, "/", > ".somesite.com"); > header("Location: > http://$SERVER_NAME$PHP_SELF?done=1"); > exit(); > } else > { > if (isset($CookieID)) > echo "Damn Cookies<br>\n"; > else > echo "Great no cookie support<br>\n"; > } > ?> > > Now onto other business, just for curiousity why do you say that if the > user can't use cookie's that your site is insecure? you know that cookie > values are stored localy on the clients computer and can be very very > easily changed right.? in netscape and IE their plain text files. just > open in notepad and change the value, restart your broser, and your done > :) > > I use setcookie() rarly and much prefer sessions. I would like more > information on why you say this. > > Chris Lee > Mediawaveonline.com > > > > > In article > <A8D9B16D2196D2118B6E00A0C9E307F43B04F0@beachpdc1.beachassociates.com>, > cday@beachassociates.com wrote: > > > I must be doing something very simple wrong.. I want to reject a user > > from my site if they aren't using cookies (for lack of a better method > > right now.. people who reject cookies can currently abuse the site I am > > working on).. > > > > I thought this code would do it: > > > > (start session)> (register var) > > > > if (!session_is_registered("my var")) { > > exit(); > > } > > > > but it doesn't work.. can someone clue me into what I'm doing wrong? > > > > Thanks, Chad Day Beach Associates > > > > When I speak german... I think german in my head... but like...Do skript > > kiddies see a w40l3 8uncha 1's and 0's and 3's and 4's and 7's in > > their > > h34d'5 w43n t43y R +a1k1n6 ? -- SirStanley > > > > > >

« previous php.general (#27873) next »