note 21430 deleted from function.md5 by jimw

From: Date: Sat, 08 Feb 2003 19:48:22 +0000
Subject: note 21430 deleted from function.md5 by jimw
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-43632@lists.php.net to get a copy of this message
You could store an md5 hash of the pass on server side, then md5 with javascript the entered pass on user side, and finally append/xor in the sessionID on both sides, re-md5 on both sides and compare notes :). Course, even if you do so, the only way to keep a ip-sniffer (who is willing to ip-forge) from then hijacking the session would be to send a random challenge (dual md5-ed with pass hash and stored in $_SESSION), and have a client side frame store the pass md5 and POST the appropriate one-shot hashed response when its ready... But if you're that paranoid you might want to just go full https://...

« previous php.notes (#43632) next »