note 37732 modified in function.setcookie by pollita
| From: | pollita@php.net | Date: | Tue, 25 Nov 2003 00:25:45 +0000 |
| Subject: | note 37732 modified in function.setcookie by pollita | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-60933@lists.php.net to get a copy of this message | ||
Note on setting cookies allowing access to sites:
If you are not using something "personal" from the computer that you are sending the
cookie too watch out. Via javascript it is possible to steal cookies from other users. Thus
allowing the stealer to login to your site as another user that might not have access otherwise.
Try to add something like the user's ip in the cookie and allowing access from that ip only
with the stored cookie data.This is the method that I use:
<?php
### functions ###
function des_cookie_encrypt($cookie_key,$data) {
// SERIALIZE ARRAY FOR TRANSPORT
$data=serialize($data);
// OPEN ENCRYPTION MODULE
$td = mcrypt_module_open(MCRYPT_DES,"",MCRYPT_MODE_ECB,"");
// CREATE IV
$iv = mcrypt_create_iv(mcrypt_enc_get_iv_size($td), MCRYPT_RAND);
// INITIALIZE MODULES
mcrypt_generic_init($td,$cookie_key,$iv);
// BASE64 ENCODE AND DES ENCRYPT
$data=base64_encode(mcrypt_generic($td, '!' . $data));
// DESTROY ENCRYPTION MODULE
mcrypt_generic_deinit($td);
return $data;
}
function des_cookie_decrypt($cookie_key, $data) {
// OPEN ENCRYPTION MODULE
$td = mcrypt_module_open(MCRYPT_DES,"",MCRYPT_MODE_ECB,"");
// CREATE
$iv = mcrypt_create_iv(mcrypt_enc_get_iv_size($td), MCRYPT_RAND);
// INITIALIZE
mcrypt_generic_init($td,$cookie_key,$iv);
// BASE64 DECODE AND DECRYPT DATA
$data=mdecrypt_generic($td, base64_decode($data));
// DESTROY DECODER
mcrypt_generic_deinit($td);
// CHECK DATA FOR TAMPERING
if(substr($data,0,1)!='!') {
// the 1st letter must always be a ! if not then someone messed with our data.
return FALSE;
}
// REMOVE THE !
$data=substr($data,1,strlen($data)-1);
// UNSERIALIZE AND RETURN
return unserialize($data);
}
function check_cookie($cookie_name,$cookie_key) {
// CHECK FOR MY COOKIE
if ( !isset( $_COOKIE[$cookie_name] )) {
return -1;
}
// DECRYPT THE COOKIE
$cookie=des_cookie_decrypt($cookie_key,$_COOKIE[$cookie_name]);
if ( $cookie === FALSE ) {
// DECRYPT FAILED DELETE COOKIE
delete_cookie($cookie_name);
return -2;
}
if ( !isset($cookie['ip']) || ($cookie['ip'] !=
$_SERVER['REMOTE_ADDR']) ) {
// COOKIE DECODED OK BUT IP DID NOT MATCH
delete_cookie($cookie_name);
return -3;
}
// UNSET THE COOKIE
unset($cookie['ip']);
return $cookie;
}
function set_cookie($cookie_name, $cookie_key, $cookie_data=array(),$time) {
$cookie_data['ip']=$_SERVER['REMOTE_ADDR'];
setcookie($cookie_name,des_cookie_encrypt( $cookie_key, $cookie_data ),$time);
return TRUE;
}
function delete_cookie($cookie_name) {
// SET COOKIE TO THE PAST
setcookie($cookie_name,"", time() - 3600);
unset($_COOKIE[$cookie_name]);
}
### end functions###
?>
Another note on storing passwords .. don't use MD5 it's too weak. The DES I used above is
only an example .. check for other methods for even stronger encyption.
Note: you will need the mcrypt module installed.
--was--
Note on setting cookies allowing access to sites:
If you are not using something "personal" from the computer that you are sending the
cookie too watch out. Via javascript it is possible to steal cookies from other users. Thus
allowing the stealer to login to your site as another user that might not have access otherwise.
Try to add something like the user's ip in the cookie and allowing access from that ip only
with the stored cookie data.This is the method that I use:
<?php
### functions ###
function des_cookie_encrypt($cookie_key,$data) {
// SERIALIZE ARRAY FOR TRANSPORT
$data=serialize($data);
// OPEN ENCRYPTION MODULE
$td = mcrypt_module_open(MCRYPT_DES,"",MCRYPT_MODE_ECB,"");
// CREATE IV
$iv = mcrypt_create_iv(mcrypt_enc_get_iv_size($td), MCRYPT_RAND);
// INITIALIZE MODULES
mcrypt_generic_init($td,$cookie_key,$iv);
// BASE64 ENCODE AND DES ENCRYPT
$data=base64_encode(mcrypt_generic($td, '!' . $data));
// DESTROY ENCRYPTION MODULE
mcrypt_generic_deinit($td);
return $data;
}
function des_cookie_decrypt($cookie_key, $data) {
// OPEN ENCRYPTION MODULE
$td = mcrypt_module_open(MCRYPT_DES,"",MCRYPT_MODE_ECB,"");
// CREATE
$iv = mcrypt_create_iv(mcrypt_enc_get_iv_size($td), MCRYPT_RAND);
// INITIALIZE
mcrypt_generic_init($td,$cookie_key,$iv);
// BASE64 DECODE AND DECRYPT DATA
$data=mdecrypt_generic($td, base64_decode($data));
// DESTROY DECODER
mcrypt_generic_deinit($td);
// CHECK DATA FOR TAMPERING
if(substr($data,0,1)!='!') {
// the 1st letter must always be a ! if not then someone messed with our data.
return FALSE;
}
// REMOVE THE !
$data=substr($data,1,strlen($data)-1);
// UNSERIALIZE AND RETURN
return unserialize($data);
}
function check_cookie($cookie_name,$cookie_key) {
// CHECK FOR MY COOKIE
if ( !isset( $_COOKIE[$cookie_name] )) {
return -1;
}
// DECRYPT THE COOKIE
$cookie=des_cookie_decrypt($cookie_key,$_COOKIE[$cookie_name]);
if ( $cookie === FALSE ) {
// DECRYPT FAILED DELETE COOKIE
delete_cookie($cookie_name);
return -2;
}
if ( !isset($cookie['ip']) || ($cookie['ip'] !=
$_SERVER['REMOTE_ADDR']) ) {
// COOKIE DECODED OK BUT IP DID NOT MATCH
delete_cookie($cookie_name);
return -3;
}
// UNSET THE COOKIE
unset($cookie['ip']);
return $cookie;
}
function set_cookie($cookie_name, $cookie_key, $cookie_data=array(),$time) {
$cookie_data['ip']=$_SERVER['REMOTE_ADDR'];
setcookie($cookie_name,des_cookie_encrypt( $cookie_key, $cookie_data ),$time);
return TRUE;
}
function delete_cookie($cookie_name) {
// SET COOKIE TO THE PAST
setcookie($cookie_name,"", time() - 3600);
unset($_COOKIE[$cookie_name]);
}
### end functions###
?>
Another note on storing passwords .. don't use MD5 it's too weak. The DES I used above is
only an example .. check for other methods for even stronger encyption.
Note: you will need the mcrypt module installed.
http://www.php.net/manual/en/function.setcookie.php