Re: password encryption ...

From: Date: Tue, 18 Jul 2000 19:21:07 +0000
Subject: Re: password encryption ...
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-7137@lists.php.net to get a copy of this message
Something like mysql_query("insert into mytable(user,password) values ('$user',password('$password'))"),$db; would do the storing A query like $sql = "SELECT *
        FROM mytable
        WHERE user='$PHP_AUTH_USER' and
password=password('$PHP_AUTH_PW')";
It would be simpler, but I don't even want to try the password if the user is from outside the acceptable IP address range for that account. I'm trying to make it expensive (in terms of time) to hack into the system. One fun function is this one: #Handle an attempt to log in from a bad IP address If (($REMOTE_ADDR < $IP_Addr_Low) or ($REMOTE_ADDR > $IP_Addr_Hi)) { sleep (rand (3,10)); echo ("Sorry, this account is not enabled for you.<BR>"); echo ("Attempt from ".$REMOTE_ADDR." logged.<BR>"); $Log_Text = "HACK,".$Reference.",".$REMOTE_ADDR.",BAD IP" ; do_action_log ($Log_Text); die (); }#End of if This makes the returning of an error message take longer, and therefore reduces my exposure to sequential attempts. Eventually, I'll add in a line so that this sort of activity generates an email to flag it, but for now, it just goes into a log file. I'll also remove the helpful text, and make it not obvious why it's dying, but while the system's under active development, I want the clues to aid me in debugging. -- www.SpamWhack.com A pre-emptive strike against spam Where's dave? http://www.findu.com/cgi-bin/find.cgi?kc6ete-9 My transistor sings with unintended parasitic the smoke escapes By Jeff Stout

« previous php.general (#7137) next »