encryption and HTTP

From: Date: Sat, 23 Feb 2002 19:20:07 +0000
Subject: encryption and HTTP
Groups: php.general 
Request: Send a blank email to php-general+get-85955@lists.php.net to get a copy of this message
Without using SSL or JavaScript, is there any way to make an md5 hash or encrypt a string before sending it out as a POST request? It seems that without encrypting the data before sending it, it can still be intercepted. Once intercepted, it doesn't matter if I use md5() on the $_POST['password'] once it gets to the script, because anyone can submit the same intercepted string to the script via POST and it will be md5()ed when it gets there, thus defeating the purpose. Maybe I haven't quite wrapped my brain around a decent authentication scheme yet. Erik ---- Erik Price Web Developer Temp Media Lab, H.H. Brown pricee@hhbrown.com

« previous php.general (#85955) next »