Something like
mysql_query("insert into mytable(user,password) values
('$user',password('$password'))"),$db;
would do the storing
A query like
$sql = "SELECT *
FROM mytable
WHERE user='$PHP_AUTH_USER' and
password=password('$PHP_AUTH_PW')";
It would be simpler, but I don't even want to try the password if the user is from outside the acceptable IP address range for that account. I'm trying to make it expensive (in terms of time) to hack into the system. One fun function is this one:
#Handle an attempt to log in from a bad IP address
If (($REMOTE_ADDR < $IP_Addr_Low) or ($REMOTE_ADDR > $IP_Addr_Hi)) {
sleep (rand (3,10));
echo ("Sorry, this account is not enabled for you.<BR>");
echo ("Attempt from ".$REMOTE_ADDR." logged.<BR>");
$Log_Text = "HACK,".$Reference.",".$REMOTE_ADDR.",BAD IP" ;
do_action_log ($Log_Text);
die ();
}#End of if
This makes the returning of an error message take longer, and therefore reduces my exposure to sequential attempts.
Eventually, I'll add in a line so that this sort of activity generates an email to flag it, but for now, it just goes into a log file. I'll also remove the helpful text, and make it not obvious why it's dying, but while the system's under active development, I want the clues to aid me in debugging.
--
www.SpamWhack.com A pre-emptive strike against spam
Where's dave?
http://www.findu.com/cgi-bin/find.cgi?kc6ete-9
My transistor sings
with unintended parasitic
the smoke escapes
By Jeff Stout