Re: WEB LOG
| From: | George Pitcher | Date: | Mon, 24 Sep 2001 14:13:49 +0000 |
| Subject: | Re: WEB LOG | ||
| References: | 1 2 3 4 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-68517@lists.php.net to get a copy of this message | ||
Hi all,
I'm new to php but I would look at the concept of setting a cookie on the
log-in page and then testing for that cookie on the http://therealsite page
and redirecting failues accordingly. In fact that could be set into every
page to make sure that people have to go thru the log-in page. You still
check for the password though.
George, a php newbie
----- Original Message -----
From: "Andreas Gietl" <a.gietl@e-admin.de>
To: "Jeffrey Paul" <sneak@datavibe.net>; "Chris Herring"
<chrisherring@subdimension.com>; "php list" <php-general@lists.php.net>
Sent: Monday, September 24, 2001 3:09 PM
Subject: Re: [PHP] WEB LOG
> On Monday 24 September 2001 16:04, Jeffrey Paul wrote:
>
> Well. If you check the HTTP_REFERER on the target-site it would work and
give
> you at least some "security". However it is still not really secure.
>
>
>
> > At 07:08 AM 9/24/2001, Chris Herring wrote:
> > >OOPS, again, elseif isn't what needs to be done.
> > >
> > >Ok, here we go.
> > >
> > >if $pwd == $real_pwd {
> > >header ("Location: http://therealsite");
> > >} else {
> > >header ("Location: http://badsite");
> > >}
> >
> > For the record, that won't stop someone from going to the destination
page
> > if the password doesn't match, which is what the person asked about.
All
> > this will do is send them a redirect to an error page if the password
> > doesn't match, it doesn't prevent anyone at all from hitting, in your
> > example, http://therealsite.
> >
> > -j
> >
> >
> > --------------------------------------------------------
> > Jeffrey Paul sneak@datavibe.net (877) 748 3467
> > ICQ: 14295546 AIM: kw34hd1 NXTL/DC: 130*21*16749
> > PGP: 0xF50BB9D7 A21AFD828C30EC77CCCC545DA0B3F501F50BB9D7
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
_________________________________________________________
Do You Yahoo!?
Get your free @yahoo.com address at http://mail.yahoo.com