in reply to Is this use of crypt() appropriate?
This is fed to MD5 which computes the checksum of it and stores it in a cookie along with the users name.
Everytime a script is requested the session id is checked by re-creating the session id and comparing it to the one in the cookie.
For someone to fake a session id they need all of the above information including the "secret" string and what order i joined them together.
The logout is simple, just delete the session id from the cookie.
More secure IMOHO than sending any form of the password over the net to store in a cookie. (Remembering it was sent once when the user logged on but for that you should use ssl).
I found this site very usuful when putting this togeather.
Good luck
Nomis52
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: Is this use of crypt() appropriate?
by Anonymous Monk on Nov 08, 2001 at 21:54 UTC | |
by Nomis52 (Friar) on Nov 09, 2001 at 05:36 UTC |