note 37732 modified in function.setcookie by pollita

From: Date: Tue, 25 Nov 2003 00:25:45 +0000
Subject: note 37732 modified in function.setcookie by pollita
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-60933@lists.php.net to get a copy of this message
Note on setting cookies allowing access to sites: If you are not using something "personal" from the computer that you are sending the cookie too watch out. Via javascript it is possible to steal cookies from other users. Thus allowing the stealer to login to your site as another user that might not have access otherwise. Try to add something like the user's ip in the cookie and allowing access from that ip only with the stored cookie data.This is the method that I use: <?php ### functions ### function des_cookie_encrypt($cookie_key,$data) { // SERIALIZE ARRAY FOR TRANSPORT $data=serialize($data); // OPEN ENCRYPTION MODULE $td = mcrypt_module_open(MCRYPT_DES,"",MCRYPT_MODE_ECB,""); // CREATE IV $iv = mcrypt_create_iv(mcrypt_enc_get_iv_size($td), MCRYPT_RAND); // INITIALIZE MODULES mcrypt_generic_init($td,$cookie_key,$iv); // BASE64 ENCODE AND DES ENCRYPT $data=base64_encode(mcrypt_generic($td, '!' . $data)); // DESTROY ENCRYPTION MODULE mcrypt_generic_deinit($td); return $data; } function des_cookie_decrypt($cookie_key, $data) { // OPEN ENCRYPTION MODULE $td = mcrypt_module_open(MCRYPT_DES,"",MCRYPT_MODE_ECB,""); // CREATE $iv = mcrypt_create_iv(mcrypt_enc_get_iv_size($td), MCRYPT_RAND); // INITIALIZE mcrypt_generic_init($td,$cookie_key,$iv); // BASE64 DECODE AND DECRYPT DATA $data=mdecrypt_generic($td, base64_decode($data)); // DESTROY DECODER mcrypt_generic_deinit($td); // CHECK DATA FOR TAMPERING if(substr($data,0,1)!='!') { // the 1st letter must always be a ! if not then someone messed with our data. return FALSE; } // REMOVE THE ! $data=substr($data,1,strlen($data)-1); // UNSERIALIZE AND RETURN return unserialize($data); } function check_cookie($cookie_name,$cookie_key) { // CHECK FOR MY COOKIE if ( !isset( $_COOKIE[$cookie_name] )) { return -1; } // DECRYPT THE COOKIE $cookie=des_cookie_decrypt($cookie_key,$_COOKIE[$cookie_name]); if ( $cookie === FALSE ) { // DECRYPT FAILED DELETE COOKIE delete_cookie($cookie_name); return -2; } if ( !isset($cookie['ip']) || ($cookie['ip'] != $_SERVER['REMOTE_ADDR']) ) { // COOKIE DECODED OK BUT IP DID NOT MATCH delete_cookie($cookie_name); return -3; } // UNSET THE COOKIE unset($cookie['ip']); return $cookie; } function set_cookie($cookie_name, $cookie_key, $cookie_data=array(),$time) { $cookie_data['ip']=$_SERVER['REMOTE_ADDR']; setcookie($cookie_name,des_cookie_encrypt( $cookie_key, $cookie_data ),$time); return TRUE; } function delete_cookie($cookie_name) { // SET COOKIE TO THE PAST setcookie($cookie_name,"", time() - 3600); unset($_COOKIE[$cookie_name]); } ### end functions### ?> Another note on storing passwords .. don't use MD5 it's too weak. The DES I used above is only an example .. check for other methods for even stronger encyption. Note: you will need the mcrypt module installed. --was-- Note on setting cookies allowing access to sites: If you are not using something "personal" from the computer that you are sending the cookie too watch out. Via javascript it is possible to steal cookies from other users. Thus allowing the stealer to login to your site as another user that might not have access otherwise. Try to add something like the user's ip in the cookie and allowing access from that ip only with the stored cookie data.This is the method that I use: <?php ### functions ### function des_cookie_encrypt($cookie_key,$data) { // SERIALIZE ARRAY FOR TRANSPORT $data=serialize($data); // OPEN ENCRYPTION MODULE $td = mcrypt_module_open(MCRYPT_DES,"",MCRYPT_MODE_ECB,""); // CREATE IV $iv = mcrypt_create_iv(mcrypt_enc_get_iv_size($td), MCRYPT_RAND); // INITIALIZE MODULES mcrypt_generic_init($td,$cookie_key,$iv); // BASE64 ENCODE AND DES ENCRYPT $data=base64_encode(mcrypt_generic($td, '!' . $data)); // DESTROY ENCRYPTION MODULE mcrypt_generic_deinit($td); return $data; } function des_cookie_decrypt($cookie_key, $data) { // OPEN ENCRYPTION MODULE $td = mcrypt_module_open(MCRYPT_DES,"",MCRYPT_MODE_ECB,""); // CREATE $iv = mcrypt_create_iv(mcrypt_enc_get_iv_size($td), MCRYPT_RAND); // INITIALIZE mcrypt_generic_init($td,$cookie_key,$iv); // BASE64 DECODE AND DECRYPT DATA $data=mdecrypt_generic($td, base64_decode($data)); // DESTROY DECODER mcrypt_generic_deinit($td); // CHECK DATA FOR TAMPERING if(substr($data,0,1)!='!') { // the 1st letter must always be a ! if not then someone messed with our data. return FALSE; } // REMOVE THE ! $data=substr($data,1,strlen($data)-1); // UNSERIALIZE AND RETURN return unserialize($data); } function check_cookie($cookie_name,$cookie_key) { // CHECK FOR MY COOKIE if ( !isset( $_COOKIE[$cookie_name] )) { return -1; } // DECRYPT THE COOKIE $cookie=des_cookie_decrypt($cookie_key,$_COOKIE[$cookie_name]); if ( $cookie === FALSE ) { // DECRYPT FAILED DELETE COOKIE delete_cookie($cookie_name); return -2; } if ( !isset($cookie['ip']) || ($cookie['ip'] != $_SERVER['REMOTE_ADDR']) ) { // COOKIE DECODED OK BUT IP DID NOT MATCH delete_cookie($cookie_name); return -3; } // UNSET THE COOKIE unset($cookie['ip']); return $cookie; } function set_cookie($cookie_name, $cookie_key, $cookie_data=array(),$time) { $cookie_data['ip']=$_SERVER['REMOTE_ADDR']; setcookie($cookie_name,des_cookie_encrypt( $cookie_key, $cookie_data ),$time); return TRUE; } function delete_cookie($cookie_name) { // SET COOKIE TO THE PAST setcookie($cookie_name,"", time() - 3600); unset($_COOKIE[$cookie_name]); } ### end functions### ?> Another note on storing passwords .. don't use MD5 it's too weak. The DES I used above is only an example .. check for other methods for even stronger encyption. Note: you will need the mcrypt module installed. http://www.php.net/manual/en/function.setcookie.php

« previous php.notes (#60933) next »