Re: Re: cvs: pearweb /public_html login.php

From: Date: Sat, 23 Nov 2002 00:37:43 +0000
Subject: Re: Re: cvs: pearweb /public_html login.php
References: 1 2  Groups: php.pear.cvs 
Request: Send a blank email to pear-cvs+get-7541@lists.php.net to get a copy of this message
> don't kid yourself, this change isn't any more secure. you're still > passing around an easily hijacked token. Of course it's more secure. Hijack the previous incarnation and the password is yours, hijack this however and you still have to crack it. > one way to make something a little less vulnerable would be to have a > cookie with the time, the user id, and a hash of those values with a > secret value (possibly the user's password). don't accept cookies that > are past some age, but issue a new one on every request (or only some > requests) with an updated timestamp and hash. And so it will be done. -- Richard Heyes V-webmail - http://www.v-webmail.co.uk

« previous php.pear.cvs (#7541) next »