note 24598 added to function.mhash
| From: | shimon_d at hotmail dot com | Date: | Thu, 22 Aug 2002 16:05:38 +0000 |
| Subject: | note 24598 added to function.mhash | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-35367@lists.php.net to get a copy of this message | ||
password security:
when you hash passwords to save them in cookie , url ,etc' my sugsession is to hash them with
date
becouse of evry body can view server log or any other loged info and reuse the hash
ie.: to re call a url eg. admin.php?user=root&passhash=5rft346tert
in this example the password keepped in secret but what stopping me to reuse the url
hash("secret") // bad security
hash("secret".date("Ymg")) // better security
// the hash good only for today
--
http://www.php.net/manual/en/function.mhash.php
http://master.php.net/manage/user-notes.php?action=edit+24598
http://master.php.net/manage/user-notes.php?action=delete+24598
http://master.php.net/manage/user-notes.php?action=reject+24598