note 27842 deleted from security.globals by aidan
| From: | aidan@php.net | Date: | Wed, 08 Sep 2004 06:05:10 +0000 |
| Subject: | note 27842 deleted from security.globals by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-76204@lists.php.net to get a copy of this message | ||
Note Submitter: s0lar1s8@_hot_mail
----
Not using the registers, I would assume that this example would also prevent a hacker from changing
the username via POST or GET, since I am setting the username cookie and hash cookie for the entire
session. The cookies are only set once and the hash key is known only to me. Example:
// Do all this before the html header - php post self
// User gave his/her username and pressed submit.
$hidden_hash_var = 'this_is_your_secret_hash_key';
if ($username) { // valid login - set cookie now for session
$id_hash= md5($username.$hidden_hash_var);
$secure = 1; // 1 for https - use 0 for http
$site = $HTTP_HOST; // your site
setcookie("username","$username",0,"/","$site",$secure);
setcookie("id_hash","$id_hash",0,"/","$site",$secure);
}
// check to see if the user is logged in (cookie set and hash matches)
$LOG_IN = 0;
if ($username && $id_hash) { // Checks each post
$hash=md5($username.$hidden_hash_var);
if ($hash == $id_hash) {
$LOG_IN = 1; // they'd have to guess this var
}
}
// end - if i'm mistaken let me know. 12/2002