Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - Usercode
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Usercode

 Post Reply Post Reply
Author
Gullanian View Drop Down
Senior Member
Senior Member
Avatar

Joined: 04 January 2002
Location: England
Status: Offline
Points: 4373
Post Options Post Options   Thanks (0) Thanks(0)   Quote Gullanian Quote  Post ReplyReply Direct Link To This Post Topic: Usercode
    Posted: 25 February 2005 at 6:53am
Trying to look at WWF login/registration system because it seems to be the best around.  I've written one with passwords in md5 with salts, changing salts etc etc, but could someone explain the function of the usercode?  Is it a constant value in the database for each user?  Is that all that is needed in a cookie to tell that you are logged in?

Thanks
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 25 February 2005 at 7:22am
The usercode system was put in along time ago.

The reason was for security, as passwords never use to be encrypted so storing the username and/or password in a cookie to track a user could course a security problem, so instead a unquie usercode field was created to track logged in users, which is stored in the cookie.

For extra security the usercode is changed when users login, edit profiles, etc.

I did consider using the ASP session ID, but the problem then is that you wouldn't be able to use the auto-login feature and you would need to login each time you cam to the forum.
Back to Top
Gullanian View Drop Down
Senior Member
Senior Member
Avatar

Joined: 04 January 2002
Location: England
Status: Offline
Points: 4373
Post Options Post Options   Thanks (0) Thanks(0)   Quote Gullanian Quote  Post ReplyReply Direct Link To This Post Posted: 25 February 2005 at 8:16am
Isn't there still the problem of if someone managed to download the database, they could find someone that hasn't logged in for a day or so, and copy the usercode value into a cookie and thus be logged in?  Or am I on the wrong lines?

If this is so, shouldn't the user have to re-enter their current password if they want to change their password for a bit mroe security?
Back to Top
Gullanian View Drop Down
Senior Member
Senior Member
Avatar

Joined: 04 January 2002
Location: England
Status: Offline
Points: 4373
Post Options Post Options   Thanks (0) Thanks(0)   Quote Gullanian Quote  Post ReplyReply Direct Link To This Post Posted: 25 February 2005 at 8:27am
Ah I see WWF does have confirm old password box, but does a problem still lie with copying the usercode into a cookie if you have access to a WWF database?
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.