Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Page 3 of 7 FirstFirst 1234567 LastLast
Results 21 to 30 of 69
  1. #21
    Join Date
    Apr 2009
    Location
    United Kingdom
    Posts
    1,111
    Tokens
    100

    Latest Awards:

    Default

    Quote Originally Posted by Lewiie15 View Post
    Yeah sure, when i first started the project i wasnt sure weather cookies or sessions were more secure, so i chose cookies. Im in the process of changing it all to sessions ect.. and ill post a sample of the main page when its complete
    K depends how you've done the cookies. They can be secure...

    As long as you're not storing the id of the user in the cookie. Or if you are then store a unique ID that is needed in the cookie that perhaps regenerates every / every few loads and they need that unique id in their cookie to be logged in or w/e.

  2. #22
    Join Date
    Sep 2009
    Location
    Hull
    Posts
    827
    Tokens
    0

    Latest Awards:

    Default

    Quote Originally Posted by BoyBetterKnow View Post
    K depends how you've done the cookies. They can be secure...

    As long as you're not storing the id of the user in the cookie. Or if you are then store a unique ID that is needed in the cookie that perhaps regenerates every / every few loads and they need that unique id in their cookie to be logged in or w/e.
    Yeah i spose. Im sure ill figure a way of doing it..

    Im gonna be at school soon so release will be delayed.

  3. #23
    Join Date
    Jun 2005
    Posts
    4,795
    Tokens
    0

    Latest Awards:

    Default

    If you can't figure that out for yourself I have serious doubts as to how well coded this project will be - especially after you critised other work. While I have no problem with your project and wish you success i'd prefer that you don't criticise other people's work for issues that you don't have sufficient knowledge in.

    Quote Originally Posted by Lewiie15 View Post
    Yeah sure, when i first started the project i wasnt sure weather cookies or sessions were more secure, so i chose cookies. Im in the process of changing it all to sessions ect.. and ill post a sample of the main page when its complete
    You just described how PHP sessions work, to some extent, (Soring the session ID in a cookie - default method) with session_regenerate_id which is a fundermental part of securing your application and should be called when the client's privileges are escalated. The session ID identifies the session data that PHP should use, therefore you need to make sure the supplied session ID is not stolen; changing the session ID, checking the IP address of the client and securing your application from XSS attacks are all essensial parts of PHP application security and will help prevent stolen session IDs being used to masquerade as authenticated clients.

    Quote Originally Posted by BoyBetterKnow View Post
    K depends how you've done the cookies. They can be secure...

    As long as you're not storing the id of the user in the cookie. Or if you are then store a unique ID that is needed in the cookie that perhaps regenerates every / every few loads and they need that unique id in their cookie to be logged in or w/e.
    Last edited by Tomm; 07-09-2009 at 05:16 PM.

  4. #24
    Join Date
    Sep 2009
    Location
    Hull
    Posts
    827
    Tokens
    0

    Latest Awards:

    Default

    Thanks for the advbice guys, im still learning as i go along.

  5. #25
    Join Date
    Apr 2009
    Location
    United Kingdom
    Posts
    1,111
    Tokens
    100

    Latest Awards:

    Default

    Quote Originally Posted by Tomm View Post
    You just described how PHP sessions work, to some extent, (Soring the session ID in a cookie - default method) with session_regenerate_id which is a fundermental part of securing your application and should be called when the client's privileges are escalated. The session ID identifies the session data that PHP should use, therefore you need to make sure the supplied session ID is not stolen; changing the session ID, checking the IP address of the client and securing your application from XSS attacks are all essensial parts of PHP application security and will help prevent stolen session IDs being used to masquerade as authenticated clients.
    Yeh That was a pretty insane explanation. Yeh I always regenerate the session id and have it in the online users table. If IDs don't match then log the user out and in some cases log it in an error table.

  6. #26
    Join Date
    Mar 2009
    Location
    Western Australia
    Posts
    386
    Tokens
    0

    Default

    Any BETA releases or test accounts?

  7. #27
    Join Date
    Oct 2008
    Posts
    736
    Tokens
    0

    Default

    has dis been released yet :p
    24-12-2008

  8. #28
    Join Date
    Mar 2009
    Location
    Western Australia
    Posts
    386
    Tokens
    0

    Default

    Hello, any updates?

  9. #29
    Join Date
    Apr 2008
    Location
    North West, UK.
    Posts
    1,007
    Tokens
    529

    Latest Awards:

    Default

    Same, update us!!

  10. #30
    Join Date
    Sep 2009
    Location
    Hull
    Posts
    827
    Tokens
    0

    Latest Awards:

    Default

    Right, update for ya.

    The name has changed to "Bobba Panel", all images are in .gif format (decreases the load time), made the panel run on SESSIONS rather than COOKIES for added security, completly new layout.

    I am currently looking for any ideas you may have for the panel.

    Previews:



Page 3 of 7 FirstFirst 1234567 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •