Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Page 2 of 2 FirstFirst 12
Results 11 to 19 of 19
  1. #11
    Join Date
    Dec 2007
    Posts
    132
    Tokens
    0

    Default

    Well I don't really know what I'm going to use it for.
    I've been thinking of a djpanel but that's already been done by a gazillion people.

    So I might try to make a website with it on my own. But before that I have to make the securiest system lol If the login page and config page aren't safe then the users wont be either.

    Php can be easy but you always have to think about the security :]

    Waz ;]


  2. #12
    Join Date
    Jul 2008
    Location
    Hastings, UK.
    Posts
    2,050
    Tokens
    0

    Latest Awards:

    Default

    Don't use shorttags! :rolleyes:

  3. #13
    Join Date
    Dec 2007
    Posts
    132
    Tokens
    0

    Default

    Lol thanks,

    I didn't really see that

    Waz ;]


  4. #14
    Join Date
    Sep 2005
    Location
    East London
    Posts
    3,028
    Tokens
    0

    Latest Awards:

    Default

    Quote Originally Posted by Iszak View Post
    Jackboy, gpc magic quotes is on by default this means all GET, POST and COOKIE are add slashes although magic quotes sybase will overwride thing. I see an ever increasing number of people using this despite not realising that their code is likely to be slashes already so it ends up being double slashes you might want to look into this wazup999.
    POST & GET :S

    I didn't know that as i have never used stripslashes on them before.

  5. #15
    Join Date
    Jun 2005
    Posts
    4,795
    Tokens
    0

    Latest Awards:

    Default

    Only had a quick glance but I noticed you are regenerating the session ID on every page load. Do not do this as you effectively break the client browser's back button and its not needed. Regenerate the session ID only when the privileges of the client are altered (e.g when logged in)

  6. #16
    Join Date
    Jun 2008
    Location
    Manchester
    Posts
    766
    Tokens
    0

    Default

    Seems pretty secure to me. There's not much point in using striptags and htmlspecialchars. One or the other will do. The secure function strips the slashes added by magic_quotes, if there are any and then adds them itself, so thats okay. An alternative would be to see if magic_quotes was on or not and decide whether to add them depending on that, like Iszak said.
    I don't really see much point in the tickets. The useragent idea is good, but won't stop someone who knows how it works from using stolen cookies. There isn't anyway cookies could be stolen from what I've seen of the script so far though.

  7. #17
    Join Date
    Oct 2007
    Posts
    824
    Tokens
    71

    Latest Awards:

    Default

    Well it's not safe anymore now that everyone on this forum can see it.
    Vouches
    [x][x]

  8. #18
    Join Date
    Jun 2008
    Location
    Manchester
    Posts
    766
    Tokens
    0

    Default

    Quote Originally Posted by Fazon View Post
    Well it's not safe anymore now that everyone on this forum can see it.
    Doesn't mean it's not safe. Just means it would be easier for someone to find vulnerabilities, if there were any.

  9. #19
    Join Date
    Dec 2007
    Posts
    132
    Tokens
    0

    Default

    @Fazon: I know the risks when I post things on a forum. This is my first login script I've ever done. So of course I'm going to have to re-write it.

    @Jxhn: I always wondered if it was bad to make the id regenerate the ID on refresh, didn't think it was really that good. And I'm still figuring out the magic quotes thing. The ticket only notices you that someone has logged in to your account and unluckily has the same ua as you.

    I still feel like it could be even safer. Guess I'll have to search on google

    Waz ;]


Page 2 of 2 FirstFirst 12

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •