Re: encryption and HTTP
| From: | Murray Chamberlain | Date: | Sun, 24 Feb 2002 18:58:06 +0000 |
| Subject: | Re: encryption and HTTP | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-86009@lists.php.net to get a copy of this message | ||
Yeah the idea of php md5() hash is for data integrity, by taking a hash of
some data and taking a hash of it later, allows you to compare the results
and see if the data hash been changed, such as a database value.
You have to use some form of client side technology to pass variables
encrypted. e.g. using Javascript or implementing SSL. U could always use
Java applets.
Muz
"Erik Price" <pricee@hhbrown.com> wrote in message
news:58E175B4-2892-11D6-9698-0050E4857868@hhbrown.com...
> Without using SSL or JavaScript, is there any way to make an md5 hash or
> encrypt a string before sending it out as a POST request?
>
> It seems that without encrypting the data before sending it, it can
> still be intercepted. Once intercepted, it doesn't matter if I use
> md5() on the $_POST['password'] once it gets to the script, because
> anyone can submit the same intercepted string to the script via POST and
> it will be md5()ed when it gets there, thus defeating the purpose.
>
> Maybe I haven't quite wrapped my brain around a decent authentication
> scheme yet.
>
>
> Erik
>
>
>
>
>
> ----
>
> Erik Price
> Web Developer Temp
> Media Lab, H.H. Brown
> pricee@hhbrown.com
>