![]() |
|
|||||||
| Notices |
| Programming Forum Web and Software Programming Forum - Java, PHP, SQL etc. |
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
||||
|
I conformed to popular demand and did a version 1.2 of my login script. Its new features include md5 encryption and the use of a database instead of variables stored in the script.
Advanced Mysql / PHP database backed login script at Pryde Design Anyway hope it helps digg // subscribe if you liked it as usual and yeah ehmm thats about it lol. Hope you like it - Andrew
__________________
Site: http://pryde-design.co.uk Blog: http://blog.pryde-design.co.uk - subscribe (pls) |
|
||||
|
ummm.. Toon, you give me sh*t about writing 2 page tutorials that directly relate to questions that people actually ask here. Hmmmmph, I better not hear another peep from you on that, brother
![]()
__________________
Tommy Logic ™ Web Design :: Valid XHTML & CSS :: SEO :: CMS :: eCommerce Web Design Tutorials :: Computer Tutorials |
|
||||
|
Were do you suggest that there is sql injection? There is only one query and that has addslashes on the only user inputed variable.
__________________
Site: http://pryde-design.co.uk Blog: http://blog.pryde-design.co.uk - subscribe (pls) Last edited by prydie; 28-03-2008 at 03:20 PM. |
|
||||
|
I'm sorry , but the addslashes class doesn't afford you any protection against SQL injection attacks. You have to detect malicious user input pro-actively using advanced error rejection exception techniques, or regular expression string rejection constructs.
__________________
Just loving the whoness of it all. |
|
||||
|
I advocate high security coding but I was trying to write a simple script for beginners to learn from. I suppose mysql_real_escape_string() could have been used but add slashes gives us the security we need here. I can't see any way to inject it but you are welcome to try. I will send it across to one of my mates in the security field and see what they think but I am confident that there is no means of exploiting the script.
__________________
Site: http://pryde-design.co.uk Blog: http://blog.pryde-design.co.uk - subscribe (pls) Last edited by prydie; 28-03-2008 at 09:47 PM. |
|
||||
|
any chance of seeing your version with the member registration bro?
__________________
Graphic Design, Illustration and Web Development UK | One Love |
|
||||
|
I will be posting it soon. I have got registration going but need to make sure that its all working properly and is totally secure.
Thanks for the interest I will post a thread about version 1.3 when I release it. - Andrew
__________________
Site: http://pryde-design.co.uk Blog: http://blog.pryde-design.co.uk - subscribe (pls) |
![]() |
|
|
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| WordPress Database Error MySQL Server has Gone Away | Graphic Design Blog | Graphic Design Blog | 0 | 02-05-2008 06:02 AM |
| PHP Login Script / form | prydie | Programming Forum | 0 | 26-03-2008 09:37 PM |
| How to Create an Advanced CSS Menu | Graphic Design Links | Graphic Design Links | 0 | 30-10-2007 01:00 PM |
| PHP Login Tutorial | PR Design | Graphic Design Tutorials | 0 | 21-09-2007 07:10 PM |
| login help plzzzzzzzz | rr_designz | Programming Forum | 2 | 21-05-2007 02:27 AM |
| All times are GMT. The time now is 05:29 AM. |
