Re: cvs: pearweb /public_html login.php
| From: | Jim Winstead | Date: | Sat, 23 Nov 2002 00:24:15 +0000 |
| Subject: | Re: cvs: pearweb /public_html login.php | ||
| References: | 1 | Groups: | php.pear.cvs |
| Request: | Send a blank email to pear-cvs+get-7540@lists.php.net to get a copy of this message | ||
Richard Heyes <richard@phpguru.org> wrote:
> richard Fri Nov 22 09:51:17 2002 EDT
>
> Modified files:
> /pearweb/public_html login.php
> Log:
> ssb you should be strung up for this :)
don't kid yourself, this change isn't any more secure. you're still
passing around an easily hijacked token.
one way to make something a little less vulnerable would be to have a
cookie with the time, the user id, and a hash of those values with a
secret value (possibly the user's password). don't accept cookies that
are past some age, but issue a new one on every request (or only some
requests) with an updated timestamp and hash.
this doesn't eliminate hijacked tokens, but at least shortens the window
of vulnerability a bit.
anyplace you want to be more paranoid, require a re-entry of the
password.
jim