Re: Re: Login/Security Problem

From: Date: Wed, 14 Nov 2001 14:54:50 +0000
Subject: Re: Re: Login/Security Problem
References: 1 2 3  Groups: php.general 
Request: Send a blank email to php-general+get-74604@lists.php.net to get a copy of this message
On Wednesday 14 November 2001 14:58, you wrote: I think mixing of the web application's and the host's operating system's authantication is not the best thing (if you don't exactly need that) The $isLogged variable that is stored in the session is perfect as long as you check that it is came from the session ($HTTP_SESSION_VARS) and you know that no one can access and write into your session files (open_basedir, and safe_mode in php.ini). Arpi > so set an md5() of each user name as "yes". > islogged=Ehyfoa74a23gfd > or whatever is good i think. but sessions are the most secure way, > so think about both (sessions and cookies) and decide what you > really need. > > you have linux? > you could make an .htaccess, and make real users with no bash, and > let them login with real usernames and passwords. > > windows? > on win2k you could do this too. but be shure to not grant access to > local hd's. major security risk... > > "Stefan Rusterholz" <scripting@interaktion.ch> schrieb im > Newsbeitrag news:009f01c16d13$bfd6b4d0$3c01a8c0@quasimodo... > > > I don't think this is a secure method. > > If I do only a little effort an find out, that it's this variable > > $islogged >

« previous php.general (#74604) next »