You are here: Re: Secure login tutorial « PHP Programming Language « IT news, forums, messages
Re: Secure login tutorial

Posted by Michael Fesser on 01/05/07 13:24

..oO(knal)

>The security part: i'm "afraid" of points one and two:
>1 - if someone listens to my traffic, what use is it to try to secure
>anything? (passw, usern. could easily be picked from the traffic)

That's what SSL (HTTPS) is for.

>I'm not affraid of the third "argument", but i read upon some other
>method where the visitor forces his own Session ID, wich replaces the
>generated one. This means he can put in there (in the session info)
>whatever he likes.

That's not possible. Manipulating the data that's stored in the session
would only be possible if you made really bad errors in your script. The
session data is stored on the server and can't be accessed directly from
the client side. Of course a user can fake his session ID, but that's
not really a problem - he just gets a new and fresh session. Trying to
guess another user's session ID in order to hijack it can be considered
impossible, unless you use network sniffing or some other dirty tricks.

Micha

 

Navigation:

[Reply to this message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация