a secure log-in system

From: ojorus (ojorus_at_hotmail.com)
Date: 01/31/04


Date: Sat, 31 Jan 2004 00:53:32 -0000

Hello!
I want to make a login system as secure as possible on a website I develop.

* The user shall log on using a Username and a password (which is stored in
a mySQL database)
*The server which I use to run my application has "register_globals"
activated (set to "on"), so that has to be taken into concideration
*The system should be secure even if the user do not click "log out" when he
is finished. (Users often just close the browser window)
*It is good if the system works even if coockies are not enabled on the
client

How can I make a login-system as secure as possible based on this?
Do I have to use session-variables, or are there other ways?

Happy for suggestions and comments on this.

regards
ojorus

-----= Posted via Newsfeeds.Com, Uncensored Usenet News =-----
http://www.newsfeeds.com - The #1 Newsgroup Service in the World!
-----== Over 100,000 Newsgroups - 19 Different Servers! =-----



Relevant Pages

  • Re: Wachovias web page security
    ... Note the URL displayed on the error message. ... that the page is secure. ... The only difference is that on my web page when you enter your username ...
    (misc.consumers)
  • Re: Authorization code for access to administration - Dialog ask for login and password three ti
    ... As you wrote that if I want more secure code, I would ask, do you ... username password pair which should be unique. ... so the query is too ambiguous for my taste. ... Injection isnt possible into the AUTH_PASSWORD variable here, ...
    (comp.lang.php)
  • Re: Cannot Access Access
    ... Use the workgroup administrator to rejoin system.mdw. ... you can use a desktop shortcut to launch your secure mdb. ... Try a username with a blank/null password. ... the wizard would have created a backup of your mdb - look in the folder for a file with the same name but a bak extension. ...
    (microsoft.public.access.security)
  • Re: WHATS BEST OF SECURITY TOKEN ?
    ... to username token, the X509 token is secure,but slow. ... or i need to buy a CA certificate from Big company,microsoft or whatever? ... > create policies will only give you a limited range of policies that you ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • Re: passing username/passwd between two processes securely...
    ... if username and paasword is in clear text on a local file, ... username/passwd in local file is not secure even we trust localsystem. ... We still feel it's not secure even we trust localsystem. ...
    (microsoft.public.win32.programmer.kernel)