3 ms·
I used this when I was doing web apps for small enterprises in early 2000's - I sent a random string in a hidden input in the login form and had some javascript
by ifdefdebug 7y ago
I used this when I was doing web apps for small enterprises in early 2000's - I sent a random string in a hidden input in the login form and had some javascript concatenate the password and the random string and send me back the username, the random string and the hash of the concatenated string. I hope I got that right (not doing web apps any more since a long time ...).
- MrStonedOne 7y agoYou would want to use a token and the string and only accept the token to look up the string that you would only accept once and for a limited time. Otherwise its vulnerable to replay attacks
- ifdefdebug 7y agoYes I think I was cashing the generated string server side for a while and checking if the string I received back had a matching entry in the cache, otherwise reject it. Anyway, it's been a long time ago, and if I had to do it again today, i would rather not roll my own.