Re: encryption and HTTP

From: Date: Sun, 24 Feb 2002 18:58:06 +0000
Subject: Re: encryption and HTTP
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-86009@lists.php.net to get a copy of this message
Yeah the idea of php md5() hash is for data integrity, by taking a hash of some data and taking a hash of it later, allows you to compare the results and see if the data hash been changed, such as a database value. You have to use some form of client side technology to pass variables encrypted. e.g. using Javascript or implementing SSL. U could always use Java applets. Muz "Erik Price" <pricee@hhbrown.com> wrote in message news:58E175B4-2892-11D6-9698-0050E4857868@hhbrown.com... > Without using SSL or JavaScript, is there any way to make an md5 hash or > encrypt a string before sending it out as a POST request? > > It seems that without encrypting the data before sending it, it can > still be intercepted. Once intercepted, it doesn't matter if I use > md5() on the $_POST['password'] once it gets to the script, because > anyone can submit the same intercepted string to the script via POST and > it will be md5()ed when it gets there, thus defeating the purpose. > > Maybe I haven't quite wrapped my brain around a decent authentication > scheme yet. > > > Erik > > > > > > ---- > > Erik Price > Web Developer Temp > Media Lab, H.H. Brown > pricee@hhbrown.com >

« previous php.general (#86009) next »