NamePros
Welcome, Guest! Ready to make a name for yourself in the domain business? We welcome both the hobbyist and professional domainer to join the discussion as part of the NamePros community.

Click here to create your profile to start earning reputation for posting, and trader ratings for buying & selling in our free e-marketplace. Build your trader rating with each successful sale. Our system has tracked over 100,000 sales and counting!
FAQ & TOS Register Search Today's Posts Mark Forums Read

Go Back   NamePros.com > Website Development Discussion Forums > Programming
Reload this Page Secure login

Programming PHP, Perl, Ruby on Rails, AJAX, HTML, XHTML, CSS, JavaScript, MySQL and any other coding topics.

Advanced Search


Closed Thread
 
LinkBack Thread Tools
Old 09-18-2003, 08:28 AM THREAD STARTER               #1 (permalink)
NamePros Member
Join Date: Jul 2003
Posts: 118
web guru is an unknown quantity at this point
 



Secure login


I have written a login script and I think I have made it as secure as possible - check session id, user ip, encrypted passwords along with a few other methods. But I have used MD5 to encrypt my passwords. This is a one way encryption method, thus even the sys admin doesent know what your password is. But what if a user forgets hi/her password. How could I go about finding it out. I was thinking about storing the password somewhere else, but then what would be the point in encrypting it in the first place? Ay one got any ideas how to go about this or even any other ideas of encrypting passwords??
web guru is offline  
Old 09-18-2003, 02:22 PM   #2 (permalink)
Senior Member
Join Date: May 2003
Posts: 2,187
adam_uk is a jewel in the roughadam_uk is a jewel in the roughadam_uk is a jewel in the rough
 


Breast Cancer
secret question

ur get the user to enter there user name and it sends an email with the pw in it to the adress in the user profile
adam_uk is offline  
Old 09-18-2003, 03:00 PM   #3 (permalink)
Senior Member
Join Date: Aug 2002
Posts: 1,255
deadserious has a spectacular aura aboutdeadserious has a spectacular aura about
 



I think you would probably want to have something like a forgot password feature and have it generate a random password and send it to the email address you have on file and of course it would need to update your system so that randomly generated password was now their password until they login and change it.

That is probably quite a bit more coding, but I think that would be about your best option if you're using one way encryption like MD5. Most, if not all of the software that I've used, which uses MD5 for passwords seems to have a feature that works this way.

Another option would be to use RC4 if you wanted a way to encrypt and decrypt passwords.
deadserious is offline  
Old 09-18-2003, 03:42 PM THREAD STARTER               #4 (permalink)
NamePros Member
Join Date: Jul 2003
Posts: 118
web guru is an unknown quantity at this point
 



Thanks dead thats a great idea!!
web guru is offline  
Old 10-08-2003, 09:50 AM   #5 (permalink)
New Member
 
$D$2's Avatar
Join Date: Oct 2003
Posts: 14
$D$2 is an unknown quantity at this point
 



Can I get a copy of this code, I would like to encrypt it into my own website!

Thanks!

P.S. Your script sounds great!
$D$2 is offline  
Old 10-08-2003, 02:24 PM   #6 (permalink)
Senior Member
Join Date: May 2003
Posts: 2,187
adam_uk is a jewel in the roughadam_uk is a jewel in the roughadam_uk is a jewel in the rough
 


Breast Cancer
Quote:
Originally posted by $D$2
????: NamePros.com http://www.namepros.com/programming/15270-secure-login.html
Can I get a copy of this code, I would like to encrypt it into my own website!

Thanks!

P.S. Your script sounds great!
why dont u make it urself
adam_uk is offline  
Old 10-08-2003, 10:29 PM   #7 (permalink)
NamePros Member
Join Date: Sep 2003
Posts: 33
Corey Bryant is an unknown quantity at this point
 



Check out: http://www.outfront.net/spooky/login.htm for a free version of a similar script.
__________________
Corey
Merchant Accounts 4 Less
Corey Bryant is offline  
Closed Thread


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools


Liquid Web Smart Servers  
All times are GMT -7. The time now is 07:32 AM.

Managed Web Hosting by Liquid Web
Domain name forum recommended by Domaining.com Powered by: vBulletin® Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.6.0 Ad Management plugin by RedTyger