GetDotted Domains

Viewing Thread:
"PHP Security Consortium"

The "Freeola Customer Forum" forum, which includes Retro Game Reviews, has been archived and is now read-only. You cannot post here or create a new thread or review on this forum.

Sun 06/02/05 at 23:04
Regular
"It goes so quickly"
Posts: 4,083
For anyone who is interested, the PHP Group have set up a PHP Security Consortium [URL]http://phpsec.org/[/URL].
Mon 07/02/05 at 08:40
Regular
"NULL"
Posts: 1,384
Manic Moaner wrote:
> I haven't read the article, but session variables are stored on the
> server, not the client. The only thing the client browser stores is
> a session id.
> Encrypting things is the session isn't therefore needed.

Oh right, cool. I've never used sessions before in PHP - I just assumed they were the same as session cookies...
Mon 07/02/05 at 08:35
Regular
Posts: 88
Nimco wrote:
> It compares what someone copies from an image into a textbox with the
> passphrase stored in a session variable. All fairly routine. However
> does mean then that session variables are completely inaccessible by
> the client? If not, surely a bot could simply copy the session
> variable into the textbox?
>

I haven't read the article, but session variables are stored on the server, not the client. The only thing the client browser stores is a session id.
Encrypting things is the session isn't therefore needed.
Sun 06/02/05 at 23:13
Regular
"NULL"
Posts: 1,384
That looks promising. Just had a quick read through the article about the Turing test thingy with the text in an image.

It compares what someone copies from an image into a textbox with the passphrase stored in a session variable. All fairly routine. However does mean then that session variables are completely inaccessible by the client? If not, surely a bot could simply copy the session variable into the textbox?

A much more secure way surely would be to put, for example, an MD5 encrypted string of the image passphrase into a session variable, and simply MD5 their input to run the match? You could do this similarly with other encryption/hashing techniques.
Sun 06/02/05 at 23:04
Regular
"It goes so quickly"
Posts: 4,083
For anyone who is interested, the PHP Group have set up a PHP Security Consortium [URL]http://phpsec.org/[/URL].

Freeola & GetDotted are rated 5 Stars

Check out some of our customer reviews below:

Easy and free service!
I think it's fab that you provide an easy-to-follow service, and even better that it's free...!
Cerrie
Wonderful...
... and so easy-to-use even for a technophobe like me. I had my website up in a couple of hours. Thank you.
Vivien

View More Reviews

Need some help? Give us a call on 01376 55 60 60

Go to Support Centre

It appears you are using an old browser, as such, some parts of the Freeola and Getdotted site will not work as intended. Using the latest version of your browser, or another browser such as Google Chrome, Mozilla Firefox, or Opera will provide a better, safer browsing experience for you.