Reply to Re: Altering users passwords

Your name:

Reply:


Posted by Shelly on 01/02/06 14:44

Side issue that just occurred to me:

I store the user's password for an app in mysql in md5 encrypted form.
Since php is run on the server, does this mean that the unencrypted
password is actually passed over the net? I assume that it is the
unencryted password that is used in the
passwd -O $oldpassword -P $newpassword $username
command.

Assuming I am correct, wouldn't sending the bare password over the net
pose a security breach? If so, how do all those web apps secure
things?

As another aside in this topic, couldn't the app (not running as root)
simply put a short file into a specified area and a cron job be running
to pick it up and to the root priv things (and then delete the file)?

Shelly


Shelly

[Back to original message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация