note 50709 deleted from function.sleep by danbrown
| From: | danbrown@php.net | Date: | Sat, 14 Mar 2009 14:38:47 +0000 |
| Subject: | note 50709 deleted from function.sleep by danbrown | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-151882@lists.php.net to get a copy of this message | ||
Note Submitter: BrianKStein at gmail dot com
----
In response to the posts below about security, you could set a MySQL or Text record using the IP
address that was logging in and then the login script would ban anyone who didn't wait the full
sleep time because their IP would be in a temporary ban list and their name would only be deleted
from that by a command after the sleep command.
<?php
//This script gets called with login params
echo "One moment while we check your username and password. DO NOT press the back button on
your browser.";
//Put the user's IP address in a text file or MySQL database
sleep(5); //5 seconds should be enough
//Delete the user's IP address used above
//Perform authentication method.
//Print some text using an if statement to notify the user whether they were right or wrong.
?>