note 27842 added to security.registerglobals

From: Date: Fri, 20 Dec 2002 15:32:29 +0000
Subject: note 27842 added to security.registerglobals
Groups: php.notes 
Request: Send a blank email to php-notes+get-41156@lists.php.net to get a copy of this message
Not using the registers, I would assume that this example would also prevent a hacker from changing the username via POST or GET, since I am setting the username cookie and hash cookie for the entire session. The cookies are only set once and the hash key is known only to me. Example: // Do all this before the html header - php post self // User gave his/her username and pressed submit. $hidden_hash_var = 'this_is_your_secret_hash_key'; if ($username) { // valid login - set cookie now for session $id_hash= md5($username.$hidden_hash_var); $secure = 1; // 1 for https - use 0 for http $site = $HTTP_HOST; // your site setcookie("username","$username",0,"/","$site",$secure); setcookie("id_hash","$id_hash",0,"/","$site",$secure); } // check to see if the user is logged in (cookie set and hash matches) $LOG_IN = 0; if ($username && $id_hash) { // Checks each post $hash=md5($username.$hidden_hash_var); if ($hash == $id_hash) { $LOG_IN = 1; // they'd have to guess this var } } // end - if i'm mistaken let me know. 12/2002 -- http://www.php.net/manual/en/security.registerglobals.php http://master.php.net/manage/user-notes.php?action=edit+27842 http://master.php.net/manage/user-notes.php?action=delete+27842 http://master.php.net/manage/user-notes.php?action=reject+27842

« previous php.notes (#41156) next »