Re: Re: cvs: pearweb /public_html login.php
| From: | Richard Heyes | Date: | Sat, 23 Nov 2002 00:37:43 +0000 |
| Subject: | Re: Re: cvs: pearweb /public_html login.php | ||
| References: | 1 2 | Groups: | php.pear.cvs |
| Request: | Send a blank email to pear-cvs+get-7541@lists.php.net to get a copy of this message | ||
> don't kid yourself, this change isn't any more secure. you're still
> passing around an easily hijacked token.
Of course it's more secure. Hijack the previous incarnation and the password
is yours, hijack this however and you still have to crack it.
> one way to make something a little less vulnerable would be to have a
> cookie with the time, the user id, and a hash of those values with a
> secret value (possibly the user's password). don't accept cookies that
> are past some age, but issue a new one on every request (or only some
> requests) with an updated timestamp and hash.
And so it will be done.
--
Richard Heyes
V-webmail - http://www.v-webmail.co.uk