Snitz Forums 2000
Snitz Forums 2000
Home | Profile | Register | Active Topics | Members | Search | FAQ
Username:
Password:
Save Password
Forgot your Password?

 All Forums
 Snitz Forums 2000 DEV-Group
 DEV Discussions (General)
 Further increase Cookie Security
 New Topic  Topic Locked
 Printer Friendly
Author Previous Topic Topic Next Topic  

Gremlin
General Help Moderator

New Zealand
7528 Posts

Posted - 09 October 2002 :  19:36:08  Show Profile  Visit Gremlin's Homepage
Was just wondering if you ever considered also encrypting the Name in the cookies as well ? Would require an extra field in the DB to hold the encrypted name and changes to any user/pass code that takes the name from the cookie, but it would double the security imo

Getting a cookie now gives you a starting point to hack an account e.g the Members Logon Name so people with "weak" passwords i.e password, bob, qwerty, fred etc could easily be guessed without the need to brute force them, encrpting the name also means a potential attacker really has nothing to go on.

Kiwihosting.Net - The Forum Hosting Specialists

James
Average Member

USA
539 Posts

Posted - 09 October 2002 :  22:35:57  Show Profile  Visit James's Homepage
I don't see where this is a help. Anybody can use the login feature to enter any name they want. Create an account and you can search the members list to find the names of other members or just look at the names on the post (doesn't require an account). Enter that name and then the easy password guesses and you basically have the same thing.

*Interested in Radio Control*
*The RC Web Board - http://www.rcwebboard.com/*
Go to Top of Page

Gremlin
General Help Moderator

New Zealand
7528 Posts

Posted - 09 October 2002 :  22:46:47  Show Profile  Visit Gremlin's Homepage
Thats is true for the particular example I gave yes.

Kiwihosting.Net - The Forum Hosting Specialists
Go to Top of Page

bjlt
Senior Member

1144 Posts

Posted - 09 October 2002 :  23:09:09  Show Profile
We can have a random login key stored in the cookie instead of the encrypted pw, which is unique and changed every time the user logs on.
see discussions here:
http://forum.snitz.com/forum/topic.asp?TOPIC_ID=33072
Go to Top of Page
  Previous Topic Topic Next Topic  
 New Topic  Topic Locked
 Printer Friendly
Jump To:
Snitz Forums 2000 © 2000-2021 Snitz™ Communications Go To Top Of Page
This page was generated in 0.58 seconds. Powered By: Snitz Forums 2000 Version 3.4.07