RE: [PHP] Checking for cookies/session_existance.. very basic.
| From: | Chad Day | Date: | Wed, 29 Nov 2000 20:42:39 +0000 |
| Subject: | RE: [PHP] Checking for cookies/session_existance.. very basic. | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-27873@lists.php.net to get a copy of this message | ||
Sending this out to the list for some more feedback..
The problem is I don't want to force a user to login to vote. If they have
cookies enabled, it stores the pictures they voted on in a session variable,
and they cannot vote until the next session. If they reject cookies, they
can vote over and over and duplicate votes are not rejected.
If I force cookies like you said, someone can write a perl/php shell script
to automatically delete the cookie, and vote again.
If I store the users IP, time, and picture ID in a table, that table would
grow very large very fast, and the time it would take to do an SELECT than
an INSERT on it would probably be adding too much overhead.
Are there any other solutions, or is the table one the one I'm stuck with,
perhaps combining that with a script to delete entries from the table older
than 1 day, or something?
(BTW -- the source code for the site I'm talking about will be open this
week, I just got the project approved on SourceForge, so I hope people don't
think I'm asking for help on something that they think I am profiting on,
etc..)
Thanks,
Chad
-----Original Message-----
From: lee@server.mediawaveonline.com
[mailto:lee@server.mediawaveonline.com]
Sent: Wednesday, November 29, 2000 3:23 PM
To: Chad Day
Subject: RE: [PHP] Checking for cookies/session_existance.. very basic.
I see perfect what your saying. That could defnitly be a problem. But even
with cookies your still going to get the guy that has his cookies enabled,
goes to the page, sets a cookie, votes, exit's his broser, deletes the
cookie, and starts over with a new cookieID.
For someone to write an simple script todo this with perl or php
(shell scripting) would be very very easy.
The only real way you can get around this is with a complicated username /
password system. If there is no cookie as the user to login or sign-up,
once a user has voted that username can't vote on that image anymore, if
the user chooses to sign-up get
email
username
email the user a temporary passwd, he can change it later. emailing the
passwd to the customer will weed out fake email address, do not allow
multiple email address's or usernames. ie if I signed up as
lee@mediawaveonline.com
username: lee
do not alow me to sign up as either
lee@mediawaveonline.com
username: chris
or
wildmanele@hotmail.com
username: lee
This will weed out alot. Now the only way for someone to vote more then
once is to have a shit load of email address's. This method isn't
completely safe either. there are ways around this, but its not going to
be easy.
If someone set's up a mailserver on their computer, and set it so that any
email, no matter the username goes to spec email address, ie. I have set
up on our server that if the receipiet does not exist I forward the email
to lostandfound@mediawaveonline.com, A person could set something up to
desceive you, but this is more unlikely and alot harder then just loging
out and re-entering your site.
There are more ways too, log the users IP, maybe they are only alowd to
vote once per 5min on an image with that IP, now the only way to get
around this is to accually disconect from the internet and re-dialin just
to vote again. there are problems with this too though, an perfect example
is here in my office we have 10 computers behind a NAT router, all 10
computers have differnt IP's internally, but to the outside work they are
all the same...
I really hope this helps, please respond back so I know how this all
worked out.
Chris Lee
Mediawaveonline.com
On Wed, 29 Nov 2000, Chad Day wrote:
> Hope you don't mind me mailing you privately.
>
> The site is xxx.xxx.xxx It starts up a session and when you
> rate a picture, it throws that picture ID into an array that's session
> registered and keeps track of what pictures you voted on, and wont let you
> vote on them again until the session closes. If they reject the cookie,
> they can vote and vote constantly. Someone did this to muck up the top 10
> lists and in general is being very annoying, so I'm trying to find a
> workaround for it.
>
> phpinfo says my configure command was:
> Configure command: './configure' '--with-mysql'
> '--with-apache=../apache_1.3.12' '--enable-track-vars'
> '--without-gd'
>
> Chad
>
> -----Original Message-----
> From: Chris Lee [mailto:lee@mediawaveonline.com]
> Sent: Tuesday, November 28, 2000 10:17 PM
> To: php-general@lists.php.net
> Subject: Re: [PHP] Checking for cookies/session_existance.. very basic.
>
>
> You probably have --enable-trans-sid enabled when you compiled php, thus
> when sessions are created they will first try cookies, if this fails it
> will automaticaly try adding PHPSESSID= to all your links.
>
> if you ONLY want to use cookie's try the setcookie() command.
>
> http://www.php.net/manual/function.setcookie.php
>
> <?
> if (!isset($done))
> {
> $CookieID = time();
> $Exp = time() + 2592000 ;
> setcookie("CookieID", $CookieID, $Exp, "/",
> ".somesite.com");
> header("Location:
> http://$SERVER_NAME$PHP_SELF?done=1");
> exit();
> } else
> {
> if (isset($CookieID))
> echo "Damn Cookies<br>\n";
> else
> echo "Great no cookie support<br>\n";
> }
> ?>
>
> Now onto other business, just for curiousity why do you say that if the
> user can't use cookie's that your site is insecure? you know that cookie
> values are stored localy on the clients computer and can be very very
> easily changed right.? in netscape and IE their plain text files. just
> open in notepad and change the value, restart your broser, and your done
> :)
>
> I use setcookie() rarly and much prefer sessions. I would like more
> information on why you say this.
>
> Chris Lee
> Mediawaveonline.com
>
>
>
>
> In article
> <A8D9B16D2196D2118B6E00A0C9E307F43B04F0@beachpdc1.beachassociates.com>,
> cday@beachassociates.com wrote:
>
> > I must be doing something very simple wrong.. I want to reject a user
> > from my site if they aren't using cookies (for lack of a better method
> > right now.. people who reject cookies can currently abuse the site I am
> > working on)..
> >
> > I thought this code would do it:
> >
> > (start session)> (register var)
> >
> > if (!session_is_registered("my var")) {
> > exit();
> > }
> >
> > but it doesn't work.. can someone clue me into what I'm doing wrong?
> >
> > Thanks, Chad Day Beach Associates
> >
> > When I speak german... I think german in my head... but like...Do skript
> > kiddies see a w40l3 8uncha 1's and 0's and 3's and 4's and 7's in
> > their
> > h34d'5 w43n t43y R +a1k1n6 ? -- SirStanley
> >
> >
>
>