Security - is this enough??
| From: | Maxwell Hung | Date: | Fri, 30 Jun 2000 09:07:52 +0000 |
| Subject: | Security - is this enough?? | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-3990@lists.php.net to get a copy of this message | ||
Hi
I wonder if I could run this by you to get some
feedback.
I have a table in the db which stores users details
name, username, password etc.. The password is
stored
using mysql password function.
When a user logs in, their username and password are
checked against the db. If they match a cookie is
set
with a random session id and their username, these
details are also entered into a table.
Every page which requires auth. checks for the
cookie
then checks the details against those stored in the
db. Obviously if someone tries to tamper with the
cookie details the info won't match that in the db
and
prompts them to relogin.
If they match it lets them in. The cookie is set to
expire after an hour and a cron job deletes the
sessions every hour.
Is this a secure enough way to prevent people
getting
into these pages. They are not mission criticle but
may contain some sensitive information. I can't use
php authentication as PHP is installed as CGI; and
it's a shared server but I know about the risks
involved there.
I know about phplib but I've already done this now.
I don't really want to use htaccess because I want
to
have a bit of personality within their pages
(welcome's etc...)
Many thanks for your time and comments.
M@X
__________________________________________________
Do You Yahoo!?
Get Yahoo! Mail - Free email you can access from anywhere!
http://mail.yahoo.com/