Today's Posts Follow Us On Twitter! TFL Members on Twitter  
Forum search: Advanced Search  
Navigation
Marketplace
  Members Login:
Lost password?
  Forum Statistics:
Forum Members: 24,254
Total Threads: 80,792
Total Posts: 566,471
There are 819 users currently browsing (tf).
 
  Our Partners:
 
  TalkFreelance     Marketplace     Looking For / Wanting to Sell Products     Other Digital Goods :

Free secure PHP login system

Thread title: Free secure PHP login system
Closed Thread  
Page 3 of 3 < 1 2 3
    Thread tools Search this thread Display Modes  
08-31-2007, 02:13 PM
#21
Sam Granger is offline Sam Granger
Status: Request a custom title
Join date: Feb 2005
Location: The Netherlands
Expertise:
Software:
 
Posts: 2,616
iTrader: 19 / 88%
 

Sam Granger is on a distinguished road

Send a message via MSN to Sam Granger

  Old

Xuxa, please justify yourself properly with examples - what makes my code "ripped"? I paid a coder to make this for me! You are accusing me of copying to code!!!

08-31-2007, 02:39 PM
#22
Immersion is offline Immersion
Status: Senior Member
Join date: Dec 2005
Location:
Expertise:
Software:
 
Posts: 918
iTrader: 5 / 100%
 

Immersion is on a distinguished road

  Old

I compared both codes side by side and there is nothing that makes them the same at all so don't worry bout xuxa.

09-03-2007, 06:10 AM
#23
kramer75 is offline kramer75
Status: I'm new around here
Join date: Sep 2007
Location:
Expertise:
Software:
 
Posts: 1
iTrader: 0 / 0%
 

kramer75 is on a distinguished road

  Old

@Immersion:

Agreed. I've had a look at the code and I can't say that they are the same either. Breaking them down and to name one of the many differences:

- The AuthClass from Sam instantiates the DB in the constructor, in the case of the cited code (by xuxa) the db link is externally passed.

- Sessions are handled discretely in separate functions in Sam's code, that is not the case in the cited code.

- There is discrete redirect handling in xuxa's cited code, no such case case for Sam's.

...

For the experienced PHP coders reading this, you'd realize that this is only a case of both coders following known industry standards of using session handling and db auth, with password hashing. All because both coders decided to resort to the standards (and frankly I find that both coders did a good job) shouldn't mean that code was 'copied'.

End of story.

09-03-2007, 11:01 AM
#24
Syke is offline Syke
Syke's Avatar
Status: Junior Member
Join date: Sep 2007
Location:
Expertise:
Software:
 
Posts: 48
iTrader: 0 / 0%
 

Syke is an unknown quantity at this point

  Old

Does this use SHA or MD5 encription?

09-03-2007, 12:15 PM
#25
Salathe is offline Salathe
Salathe's Avatar
Status: Community Archaeologist
Join date: Jul 2004
Location: Scotland
Expertise: Software Development
Software: vim, PHP
 
Posts: 3,820
iTrader: 25 / 100%
 

Salathe will become famous soon enough

Send a message via MSN to Salathe

  Old

Originally Posted by Syke View Post
Does this use SHA or MD5 encription?
A cursory glance at the code would reveal your answer: MD5.

09-03-2007, 12:46 PM
#26
Sam Granger is offline Sam Granger
Status: Request a custom title
Join date: Feb 2005
Location: The Netherlands
Expertise:
Software:
 
Posts: 2,616
iTrader: 19 / 88%
 

Sam Granger is on a distinguished road

Send a message via MSN to Sam Granger

  Old

Originally Posted by Syke View Post
Does this use SHA or MD5 encription?
MD5 but easy to change into SHA

09-03-2007, 02:20 PM
#27
Syke is offline Syke
Syke's Avatar
Status: Junior Member
Join date: Sep 2007
Location:
Expertise:
Software:
 
Posts: 48
iTrader: 0 / 0%
 

Syke is an unknown quantity at this point

  Old

But I heard that SHA is lot better than MD5. So is it safe to use this script?

09-03-2007, 03:28 PM
#28
Sam Granger is offline Sam Granger
Status: Request a custom title
Join date: Feb 2005
Location: The Netherlands
Expertise:
Software:
 
Posts: 2,616
iTrader: 19 / 88%
 

Sam Granger is on a distinguished road

Send a message via MSN to Sam Granger

  Old

Originally Posted by Syke View Post
But I heard that SHA is lot better than MD5. So is it safe to use this script?
Yes, SHA is more secure but this script is still safe. If wanted, I can also provide you with a SHA version.

09-03-2007, 04:57 PM
#29
Immersion is offline Immersion
Status: Senior Member
Join date: Dec 2005
Location:
Expertise:
Software:
 
Posts: 918
iTrader: 5 / 100%
 

Immersion is on a distinguished road

  Old

SHA is better, less chance of being brocken through brute force. Yet you could easy have a encryption key (word) that you append to the end of say the passwords and then md5hash it. Then when you compare a login to the database entry you just append again as the word wont change and then hash.

That makes it alot harder as they wont be able to use a dictionary and would need to know the key.

Closed Thread  
Page 3 of 3 < 1 2 3


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

  Posting Rules  
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump:
 
  Contains New Posts Forum Contains New Posts   Contains No New Posts Forum Contains No New Posts   A Closed Forum Forum is Closed