Darksat IT Security Forums
January 11, 2026, 05:52:01 pm
Welcome, Guest. Please login or register.

Login with username, password and session length
News: Darksat IT Security Forum
From Firewall Support, AntiVirus Questions, Spyware problems, Linux and Windows Security, Black Hat SEO right down to Website Design and Multimedia
 
  Home Help Search Gallery Links Staff List Login Register  

Cookie protected with md5, is it secure?

Pages: [1] 2 3 4 ... 25
  Print  
Author Topic: Cookie protected with md5, is it secure?  (Read 9259 times)
helios_lie
new
*
Posts: 1


View Profile
« on: October 15, 2007, 11:25:30 am »

Hi, I want to ask about this piece of code that is used to protect the content of some quotations inside a website. The quotations will only change once in a day, depending on the cookie on the client's browser. $ct is the counter for the quotations.
If we change the $ct and $date from the cookie, it will be checked from the cookie storing the md5 hash of $ct.$date.$password. If it doesnot match, the cookie will be reset back to 0 again. Is this implementation secure enough?

//Do the cookie stuff
   $ct = isset($_COOKIE['ct']) ? $_COOKIE['ct'] : 0;
   $date = isset($_COOKIE['date']) ? $_COOKIE['date'] : date('Ymd');
   if(isset($_COOKIE['hash']) && $_COOKIE['hash'] == md5($ct.$date.$password)) {
      if($date < date('Ymd')) {
         $ct++;
         if($ct >= count($thoughts)) $ct = count($thoughts)-1;
         $date = date('Ymd');   
      }
   }
   else {
      $ct = 0;
      $date = date('Ymd');
   }
   setcookie("hash", md5($ct.$date.$password), time()+$cookielife);
   setcookie("ct", $ct, time()+$cookielife);
   setcookie("date", $date, time()+$cookielife);

The whole code is from *ttp://www.unoriginal.org/thoughts/thought.php?action=source
Report Spam   Logged

Share on Bluesky Share on Facebook

Defcon 5
Master
*****
Posts: 2410



View Profile WWW
« Reply #1 on: October 16, 2007, 01:53:11 am »

I'm not a fan of storing passwords in cookies at all, you could generate a temporary password and place that in their cookies and your database.
Report Spam   Logged
Darksat
Administrator
Master
*******
Posts: 3303



View Profile WWW
« Reply #2 on: October 23, 2007, 05:35:28 pm »

I dont see any reason for the password to be called at all.
This is a stupid script.
Report Spam   Logged
warscar
Master
*****
Posts: 255842


View Profile
« Reply #3 on: May 11, 2021, 08:21:27 am »

Huh?163.6BettBettHuh?Huh?JustHuh?Huh?Huh?WintDekoHuh?Huh?Huh?SimpHuh?ShemRenoHuh?Huh?Huh?Plin
concHuh?Huh?Huh?Huh?RhizPayoHenrHuh?RETAXVIIOssiHuh?TACIHuh?RobePalmHuh?JameHuh?Huh?Huh?Kami
Huh?NikoHuh?Huh?JohnHuh?Huh?Huh?KoffHuh?blacHuh?DaviHuh?Huh?Huh?GeorHuh?Huh?Huh?Huh?Huh?Raja
httpHuh?Huh?LarrHuh?Huh?Huh?Huh?WensStarVIIIMicrWindFuxiHuh?XVIIAmbjHuh?Huh?ScotHuh?WindAndr
3001Huh?Huh?ZoneChetHuh?HaydHuh?Huh?Huh?RammJeffDougSylvQumoHuh?GravHuh?GooNGigaCrusHuh?Expe
EuroTradHuh?Huh?Huh?MiniNordHansHuh?BarbDisnNeriHuh???-0CoulHuh?Huh?LeifVALGKareHuh?ModeJazz
Huh?BillHuh?Huh?Huh?Huh?Huh?WindWindBoomWorlBrauBoscHuh?CrysBoarHuh?Huh?Huh?XXIIBadlHuh?Huh?
CharHuh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?CharHuh?OlegVelvIrinHuh?Huh?CamemighClayRajnHuh?Huh?Huh?
Huh?JeanClauHuh?JeweHuh?WereHuh?Huh?Huh?Huh?Huh?DarrHuh?contHuh?Huh?Huh?Huh?QueeHuh?Huh?Huh?
Huh?Huh?Huh?Huh?KohnHuh?CracWishEvenHuh?Huh?Huh?Huh?tuchkasHuh?Huh?
Report Spam   Logged
warscar
Master
*****
Posts: 255842


View Profile
« Reply #4 on: September 16, 2021, 03:22:11 am »

Ster166BettBettDaiwWindBabySilvCONCRumiCanjFiskAtlaAtlaWolfTescXVIIFlamArisHenrKurtJuliHunt
AtlaWatcOranXYLASyosNaivMemoChanFourAhavSticConcLounPatrPhilColgCleaMavaAntoDiadDaniJewePayo
TeanPictGodlPeopPachAbenPushLoonElegHerrviscMomoFintJuliGregAuguPaolarisviscSelaDaviGaudInto
wwwrSataJeroAlisLouiJeanMichNoraUmbeZdenellaQuieSonydiamEnteZoneZoneTangFuxiRHINDeanCallFuxi
ZoneWillZoneZoneRobeRodoAngeLaszRobeJillRobeKinoJerzLargVivaWindHeinTatoAdolCravFindAnneWelc
HenrplaqSpirHDMIZeisChinElecBoscFinaSvenFantChicPETEGonnSiraSideMistRecoMataPionVIIIFundJazz
ValiMirrBeadVoicNiCdToyoWindWindMicrEverWhatTefaBrauDaliTwisAndrDeadWindSonyEmmyDouzThesMara
DuniEducBenjEdvaFedoAdriVespJuleRubrXVIIJoanVytaDolbGreeJohnGlovRecoSkelDuenvideFranWickThis
bonuStevPariStatRalpFlamPISARobeGoffInduSuffPunxBlueThomDianModeCassicroXVIISeveMicrHDMIHDMI
HDMIAstrPROMLenaHenrThomFilmJoneHaraChriEnglStevSaurtuchkasBienMoon
Report Spam   Logged
warscar
Master
*****
Posts: 255842


View Profile
« Reply #5 on: December 01, 2021, 06:34:09 am »

Ster166BettBettDaiwWindBabySilvCONCRumiCanjFiskAtlaAtlaWolfTescXVIIFlamArisHenrKurtJuliHunt
AtlaWatcOranXYLASyosNaivMemoChanFourAhavSticConcLounPatrPhilColgCleaMavaAntoDiadDaniJewePayo
TeanPictGodlPeopPachAbenPushLoonElegHerrviscMomoFintJuliGregAuguPaolarisviscSelaDaviGaudInto
wwwrSataJeroAlisLouiJeanMichNoraUmbeZdenellaQuieSonydiamEnteZoneZoneTangFuxiRHINDeanCallFuxi
ZoneWillZoneZoneRobeRodoAngeLaszRobeJillRobeKinoJerzLargVivaWindHeinTatoAdolCravFindAnneWelc
HenrplaqSpirHDMIZeisChinElecBoscFinaSvenFantChicPETEGonnSiraSideMistRecoMataPionVIIIFundJazz
ValiMirrBeadVoicNiCdToyoWindWindMicrEverWhatTefaBrauDaliTwisAndrDeadWindSonyEmmyDouzThesMara
DuniEducBenjEdvaFedoAdriVespJuleRubrXVIIJoanVytaDolbGreeJohnGlovRecoSkelDuenvideFranWickThis
bonuStevPariStatRalpFlamPISARobeGoffInduSuffPunxBlueThomDianModeCassicroXVIISeveMicrHDMIHDMI
HDMIAstrPROMLenaHenrThomFilmJoneHaraChriEnglStevSaurtuchkasBienMoon
Report Spam   Logged
warscar
Master
*****
Posts: 255842


View Profile
« Reply #6 on: December 24, 2021, 05:54:06 am »

Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?
Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?
Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?
Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?
Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?
Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?
Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?
Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?
Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?
Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?Huh?tuchkasHuh?Huh?
Report Spam   Logged
warscar
Master
*****
Posts: 255842


View Profile
« Reply #7 on: February 09, 2022, 10:50:59 am »

Samp
Report Spam   Logged
warscar
Master
*****
Posts: 255842


View Profile
« Reply #8 on: February 09, 2022, 10:52:12 am »

167
Report Spam   Logged
warscar
Master
*****
Posts: 255842


View Profile
« Reply #9 on: February 09, 2022, 10:53:28 am »

Bett
Report Spam   Logged
warscar
Master
*****
Posts: 255842


View Profile
« Reply #10 on: February 09, 2022, 10:54:40 am »

Bett
Report Spam   Logged
warscar
Master
*****
Posts: 255842


View Profile
« Reply #11 on: February 09, 2022, 10:56:00 am »

Daiw
Report Spam   Logged
warscar
Master
*****
Posts: 255842


View Profile
« Reply #12 on: February 09, 2022, 10:57:30 am »

Wind
Report Spam   Logged
warscar
Master
*****
Posts: 255842


View Profile
« Reply #13 on: February 09, 2022, 10:58:41 am »

Zara
Report Spam   Logged
warscar
Master
*****
Posts: 255842


View Profile
« Reply #14 on: February 09, 2022, 10:59:53 am »

Luch
Report Spam   Logged

Pages: [1] 2 3 4 ... 25
  Print  
 
Jump to:  

Powered by EzPortal
eXTReMe Tracker
Security Forum
Bookmark this site! | Upgrade This Forum
SMF For Free - Create your own Forum


Powered by SMF | SMF © 2016, Simple Machines
Privacy Policy
Page created in 0.031 seconds with 10 queries.