Re: cvs: pearweb /public_html login.php

From: Date: Sat, 23 Nov 2002 00:24:15 +0000
Subject: Re: cvs: pearweb /public_html login.php
References: 1  Groups: php.pear.cvs 
Request: Send a blank email to pear-cvs+get-7540@lists.php.net to get a copy of this message
Richard Heyes <richard@phpguru.org> wrote: > richard Fri Nov 22 09:51:17 2002 EDT > > Modified files: > /pearweb/public_html login.php > Log: > ssb you should be strung up for this :) don't kid yourself, this change isn't any more secure. you're still passing around an easily hijacked token. one way to make something a little less vulnerable would be to have a cookie with the time, the user id, and a hash of those values with a secret value (possibly the user's password). don't accept cookies that are past some age, but issue a new one on every request (or only some requests) with an updated timestamp and hash. this doesn't eliminate hijacked tokens, but at least shortens the window of vulnerability a bit. anyplace you want to be more paranoid, require a re-entry of the password. jim

« previous php.pear.cvs (#7540) next »