note 21430 deleted from function.md5 by jimw
| From: | jimw@php.net | Date: | Sat, 08 Feb 2003 19:48:22 +0000 |
| Subject: | note 21430 deleted from function.md5 by jimw | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-43632@lists.php.net to get a copy of this message | ||
You could store an md5 hash of the pass on server side, then md5 with javascript the entered pass on
user side, and finally append/xor in the sessionID on both sides, re-md5 on both sides and compare
notes :).
Course, even if you do so, the only way to keep a ip-sniffer (who is willing to ip-forge) from
then hijacking the session would be to send a random challenge (dual md5-ed with pass hash and
stored in $_SESSION), and have a client side frame store the pass md5 and POST the appropriate
one-shot hashed response when its ready...
But if you're that paranoid you might want to just go full https://...