Web Analytics Made Easy -
StatCounter I was told it couldn't be done and LOOK! - CodingForum


No announcement yet.

I was told it couldn't be done and LOOK!

  • Filter
  • Time
  • Show
Clear All
new posts

  • I was told it couldn't be done and LOOK!

    I have spent some time trying to create a secure login on client side programming. I think I have completed my mission. Let me know if you can by pass the login to the data on the other side.

    Biblical Research Online
    Last edited by Vapor; Jul 29, 2005, 01:34 AM.

  • #2
    I have to say, that's quite clever. It wouldn't survive a brute-force attack, but to protect a Geocities site it seems good enough.
    Forget style. Code to semantics. Seperate style from structure, and structure from behaviour.
    I code to specs, and test only in Firefox (unless stated otherwise).


    • #3
      It's basically the same as the other JS password protection methods in that you just send them to password.html, except you include username_and_password.js which draws the secured content. It's not something people can crack without getting a directory index to see which files you have in your folders.
      offtone.com | offtonedesign.com


      • #4
        It seems safe enough for your site, but it could easily be passed by bruteforcing it or running a dictionary attack. You'd have to know someones username though, if not it would take a million years.
        <JPM />


        • #5
          I wouldn't call your login secure. Several issues I can think of make such a script less attractive than a server-side login:

          1) Once you are logged in you are logged in. There is no "session expiration".
          2) You don't need to know the username and password. You only need to know the filename you are redirected after logging in.
          3) If you occasionally change the filename of the file, you are redirected to, for security reasons (I assume there is no other way to protect against brute force methods) you will break existing links and bookmarks
          4) You cannot set different "access levels/rights" for members

          Last edited by dumpfi; Jul 29, 2005, 12:15 PM.
          "Failure is not an option. It comes bundled with the software."
          Little did the bunnies suspect that one of them was a psychotic mass murderer with a 6 ft. axe.


          • #6
            Thank you,


            Your are correct on the session expiration and such, but I can make it so that you can not see what the page url is, thus, creating a dang near impossible crack unless you either know a username and password.

            However there is still that "brute force" that might get in. Althought there is no real sensitive info that is SUPER important


            • #7
              and the "history" button on the browser?

              They would have to erase that every time if anyone else
              uses their computer.


              • #8

                Good thinking! That history could be the main problem I face. Never thought about that. Then, anyone who used the same computer could see.

                Is there any kind of code you can stick in with the html to either hide or clear the history from being revealed?


                • #9

                  What kind of information is on your member pages that needs to be secret?

                  Knowing what the member pages look like might allow us to give you some
                  more ideas. Better yet, create a fake member and give us the link to your
                  site so we can see what it looks like.


                  • #10
                    Is this your members only page?


                    If so, change the file name, I guessed it on my first try.


                    • #11
                      this won't help bruteforcing, but a good idea if you don't want people looking over your shoulder at the url (which has the password in it), write the name of the target page in hex. that way, they won't remember the code (unless they have photographic memory)
                      i'm only 12, gimme some slack


                      • #12
                        Great Idea!

                        I was thinking about changing the pages to hex values earlier!


                        • #13

                          The new and even better site stands to this day! I have used hex values that complicate even brute force attacks! Generic names (such as members.htm, etc...) no longer stand. Making it very difficult to bypass.

                          Thanks for the tips!


                          • #14
                            Are you going to post the code so others can use this as this is probably the BEST client-side login.
                            Get Mozilla Firefox


                            • #15
                              Any client side login isn't secure....I don't want to use it, lol.