Important alert: (current site time 7/15/2013 11:04:28 AM EDT)
 

winzip icon

A java / php login script

Email
Submitted on: 4/20/2003 11:28:09 AM
By: gmtt_dan  
Level: Beginner
User Rating: By 2 Users
Compatibility: PHP 3.0, PHP 4.0
Views: 36946
(About the author)
 
     This gives a simple secure login script for basic pages, such as clan member pages, It is a simple php secure login script using java and php. The login code is pure java, however the password could be seen by going to view source. By encasing these parts in php tags, they cannot be viewed in the source, therefore making it secure. The username and password are entered at the top. Edit From lines 44 onwards to change the members page. The original Java Script just linked to a new page, if the login was correct. This made a second security issue because people could access the member page by going to www.youurl.com/members.php. In release 0.1b the members page is included in login.php which though still posing a potential security risk, it's much harder for people who don't know the password to get access to.
 
winzip iconDownload code

Note: Due to the size or complexity of this submission, the author has submitted it as a .zip file to shorten your download time. Afterdownloading it, you will need a program like Winzip to decompress it.Virus note:All files are scanned once-a-day by Planet Source Code for viruses, but new viruses come out every day, so no prevention program can catch 100% of them. For your own safety, please:
  1. Re-scan downloaded files using your personal virus checker before using it.
  2. NEVER, EVER run compiled files (.exe's, .ocx's, .dll's etc.)--only run source code.

If you don't have a virus scanner, you can get one at many places on the net including:McAfee.com

 
Terms of Agreement:   
By using this code, you agree to the following terms...   
  1. You may use this code in your own programs (and may compile it into a program and distribute it in compiled format for languages that allow it) freely and with no charge.
  2. You MAY NOT redistribute this code (for example to a web site) without written permission from the original author. Failure to do so is a violation of copyright laws.   
  3. You may link to this code from another website, but ONLY if it is not wrapped in a frame. 
  4. You will abide by any additional copyright restrictions which the author may have placed in the code or code's description.


Other 12 submission(s) by this author

 


Report Bad Submission
Use this form to tell us if this entry should be deleted (i.e contains no code, is a virus, etc.).
This submission should be removed because:

Your Vote

What do you think of this code (in the Beginner category)?
(The code with your highest vote will win this month's coding contest!)
Excellent  Good  Average  Below Average  Poor (See voting log ...)
 

Other User Comments

4/21/2003 2:34:38 AMBeRtJeKnOrR

you just echo the user+pass in the javascript so you can still see the user+pass in view source, i dont see whats better about it than a normal javascript login
(If this comment was disrespectful, please report it.)

 
4/21/2003 8:55:42 AMHell_Freezer

ah thats right you do.....
i'll have to encse it all in php
(If this comment was disrespectful, please report it.)

 
4/21/2003 8:56:31 AMHell_Freezer

the only thing that makes it better is maybe that the members page is included in login.php which stops people going to www.whatever.com/member.html.....
but anyway thanks for pointing that out
(If this comment was disrespectful, please report it.)

 
4/21/2003 9:04:09 AMHell_Freezer

hm....i'll look further into that...
(If this comment was disrespectful, please report it.)

 
5/2/2003 7:08:36 PMSteven M B.

Why don't you look into sessions and MySQL, hell even using php and an htaccess .htpasswd file is easy enough to do, as well as sessions.
(If this comment was disrespectful, please report it.)

 
7/4/2003 4:46:19 AMHell_Freezer

aye yeah i know howto do all that :)
see www.clanef.co.uk/ladder for some of my finest work. It was just an idea i thought might work, then realised didn't, but i was hoping by putting the password in the php tags, it would stop it being shown in the source. But it didnt. Never mind, htaccess is a million times better anyway.
(If this comment was disrespectful, please report it.)

 
6/14/2004 8:55:46 AMiwan

1. Javascript != Java
2. This aint very secure. Dont use it for anything serious.
(If this comment was disrespectful, please report it.)

 
6/14/2004 1:11:31 PMShatners

Haha yeah thats true. Anyway this was done way back in my silly misinformed youth. Check out my lite login system (here or on www.gmtt.co.uk) it's much better.
(If this comment was disrespectful, please report it.)

 
9/24/2004 3:49:16 AMpawanfx

www.sansinfo.cjb.net
(If this comment was disrespectful, please report it.)

 
7/15/2006 5:49:33 AMrajesh

Thanks u have given a great plateform

(If this comment was disrespectful, please report it.)

 

Add Your Feedback
Your feedback will be posted below and an email sent to the author. Please remember that the author was kind enough to share this with you, so any criticisms must be stated politely, or they will be deleted. (For feedback not related to this particular code, please click here instead.)
 

To post feedback, first please login.