GetDotted Domains

Viewing Thread:
"PHP Security Consortium"

The "Freeola Customer Forum" forum, which includes Retro Game Reviews, has been archived and is now read-only. You cannot post here or create a new thread or review on this forum.

Sun 06/02/05 at 23:04
Regular
"It goes so quickly"
Posts: 4,083
For anyone who is interested, the PHP Group have set up a PHP Security Consortium [URL]http://phpsec.org/[/URL].
Sun 06/02/05 at 23:04
Regular
"It goes so quickly"
Posts: 4,083
For anyone who is interested, the PHP Group have set up a PHP Security Consortium [URL]http://phpsec.org/[/URL].
Sun 06/02/05 at 23:13
Regular
"NULL"
Posts: 1,384
That looks promising. Just had a quick read through the article about the Turing test thingy with the text in an image.

It compares what someone copies from an image into a textbox with the passphrase stored in a session variable. All fairly routine. However does mean then that session variables are completely inaccessible by the client? If not, surely a bot could simply copy the session variable into the textbox?

A much more secure way surely would be to put, for example, an MD5 encrypted string of the image passphrase into a session variable, and simply MD5 their input to run the match? You could do this similarly with other encryption/hashing techniques.
Mon 07/02/05 at 08:35
Regular
Posts: 88
Nimco wrote:
> It compares what someone copies from an image into a textbox with the
> passphrase stored in a session variable. All fairly routine. However
> does mean then that session variables are completely inaccessible by
> the client? If not, surely a bot could simply copy the session
> variable into the textbox?
>

I haven't read the article, but session variables are stored on the server, not the client. The only thing the client browser stores is a session id.
Encrypting things is the session isn't therefore needed.
Mon 07/02/05 at 08:40
Regular
"NULL"
Posts: 1,384
Manic Moaner wrote:
> I haven't read the article, but session variables are stored on the
> server, not the client. The only thing the client browser stores is
> a session id.
> Encrypting things is the session isn't therefore needed.

Oh right, cool. I've never used sessions before in PHP - I just assumed they were the same as session cookies...

Freeola & GetDotted are rated 5 Stars

Check out some of our customer reviews below:

Great services and friendly support
I have been a subscriber to your service for more than 9 yrs. I have got at least 12 other people to sign up to Freeola. This is due to the great services offered and the responsive friendly support.
First Class!
I feel that your service on this occasion was absolutely first class - a model of excellence. After this, I hope to stay with Freeola for a long time!

View More Reviews

Need some help? Give us a call on 01376 55 60 60

Go to Support Centre
Feedback Close Feedback

It appears you are using an old browser, as such, some parts of the Freeola and Getdotted site will not work as intended. Using the latest version of your browser, or another browser such as Google Chrome, Mozilla Firefox, or Opera will provide a better, safer browsing experience for you.