You are here: Re: is it safe to store a cookie user id as a login for my site « PHP Programming Language « IT news, forums, messages
Re: is it safe to store a cookie user id as a login for my site

Posted by Jerry Stuckle on 02/16/07 15:27

Mike Roetgers wrote:
> monomaniac21 schrieb:
>> hi
>>
>> i have a php site which allows users to save a cookie on their
>> computer which stores their user id details and allows them to auto-
>> login.
>>
>> i'm wondering whether this is safe, is it possible for a malicious
>> user to find that cookie and change its value and therefore auto-login
>> as someone else? and if so how can this be prevented?
>>
>> thanks
>>
>> marc
>>
> You could store one half of the user's password hash in the cookie. When
> he come back, you compare it to the hash in the db. Works for me :-)

Or, better yet, hash the password in the database a second time and
store that has in the cookie. When they do the cookie login compare the
cookie they send with the database password (after you've hashed it, of
course).

--
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@attglobal.net
==================

 

Navigation:

[Reply to this message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация