Php Logon System

Discussion in 'PHP' started by nrodes, Oct 5, 2008.

  1. #1
    Somebody told me that a logon script based on:

    if($username == "User" & $password == "Pass"){
    //set sessions etc here
    }


    was secure.

    I have trouble believing this because it seems like anybody could view the php file with a text editor and see the username and password.

    Were they right?
     
    nrodes, Oct 5, 2008 IP
  2. AT-XE

    AT-XE Peon

    Messages:
    676
    Likes Received:
    15
    Best Answers:
    0
    Trophy Points:
    0
    #2
    well, no, if you upload the php file to a server that supports php the php contents will not be visible, however the html source code could be seen, otherwise yes it's secure.
     
    AT-XE, Oct 5, 2008 IP
  3. mehdi

    mehdi Peon

    Messages:
    258
    Likes Received:
    12
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Yes, its the basic start to PHP login system.... u can start your learning from here.!
    Make sure this start is very insecure.
     
    mehdi, Oct 5, 2008 IP
  4. techcone

    techcone Banned

    Messages:
    206
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #4
    PHP files cannot be viewed in browser.

    Browser can only render HTML.

    PHP is processed by server and then send to client pc.
     
    techcone, Oct 5, 2008 IP
  5. fireworking

    fireworking Peon

    Messages:
    460
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #5
    A login system is way more complex. I learned how to do it very well with Larry Ullman's PHP6 and Mysql 5 Book 3rd edition. You should check it out. Includes a forums and e commerce example.
     
    fireworking, Oct 5, 2008 IP
  6. Panzer

    Panzer Active Member

    Messages:
    381
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    58
    #6
    Its not a good user login system. If the password is compromised then your whole system is gone. I'd recommend one that has a MySQL backend.
     
    Panzer, Oct 5, 2008 IP
  7. Dman91

    Dman91 Peon

    Messages:
    46
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    0
    #7
    go for some database (mysql) and encrypt your passwords so they are more secure
     
    Dman91, Oct 5, 2008 IP