<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=PHP_Project_Authentication</id>
		<title>PHP Project Authentication - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=PHP_Project_Authentication"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=PHP_Project_Authentication&amp;action=history"/>
		<updated>2026-04-30T14:59:11Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=PHP_Project_Authentication&amp;diff=206968&amp;oldid=prev</id>
		<title>Imifos at 11:03, 21 January 2016</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=PHP_Project_Authentication&amp;diff=206968&amp;oldid=prev"/>
				<updated>2016-01-21T11:03:40Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 11:03, 21 January 2016&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l61&quot; &gt;Line 61:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 61:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[PHP Security for Developers]]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[PHP Security for Developers]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;OWASP &lt;/del&gt;PHP &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Project&lt;/del&gt;]]&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:PHP]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Imifos</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=PHP_Project_Authentication&amp;diff=9699&amp;oldid=prev</id>
		<title>Vanderaj at 01:56, 15 September 2006</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=PHP_Project_Authentication&amp;diff=9699&amp;oldid=prev"/>
				<updated>2006-09-15T01:56:23Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;=Authentication principles=&lt;br /&gt;
==Evidence of identity==&lt;br /&gt;
==Self registration==&lt;br /&gt;
==Remember Me==&lt;br /&gt;
==Account controls==&lt;br /&gt;
&lt;br /&gt;
Account Expiry&lt;br /&gt;
&lt;br /&gt;
=Authentication methods=&lt;br /&gt;
==Forms based authentication==&lt;br /&gt;
==LDAP authentication==&lt;br /&gt;
==Strong Authentication==&lt;br /&gt;
&lt;br /&gt;
=Programmatic patterns=&lt;br /&gt;
==Positive Authentication==&lt;br /&gt;
==Multiple Key Lookups==&lt;br /&gt;
==Browser remembers passwords==&lt;br /&gt;
==Change passwords==&lt;br /&gt;
==Brute Force==&lt;br /&gt;
==Idle Timeouts==&lt;br /&gt;
==Logout==&lt;br /&gt;
&lt;br /&gt;
=Anti security patterns=&lt;br /&gt;
==Default accounts==&lt;br /&gt;
==Choice of usernames==&lt;br /&gt;
==CAPTCHA==&lt;br /&gt;
==Weak password controls==&lt;br /&gt;
==Reversible password encryption==&lt;br /&gt;
==Automated password resets==&lt;br /&gt;
&lt;br /&gt;
Automated password reset schemes are a weak backdoor password into your system. If your system is worthless, then automated password resets might be for you. However, in most cases, they are unsuitable. &lt;br /&gt;
&lt;br /&gt;
Automated password resets take two forms:&lt;br /&gt;
&lt;br /&gt;
* Send e-mail to registered user's e-mail address&lt;br /&gt;
* Questions and answers&lt;br /&gt;
&lt;br /&gt;
Sending e-mail is suspect due to the ease of which web mail and POP3 / IMAP mail may be compromised, particularly if the user chooses the same password amongst many systems. Often the user's e-mail address is easily determined using search engines, and so an attacker can try to brute force the web mail / POP / IMAP account and thus gain control of your system's credential. &lt;br /&gt;
&lt;br /&gt;
Questions and answers are highly problematic in countries with strong privacy laws. You MUST not collect data which you have no need to collect. A questions and answers scenario is not a permissable use for items such as:&lt;br /&gt;
&lt;br /&gt;
* Social security numbers or tax file numbers&lt;br /&gt;
* Information about other individuals (mother's maiden name, birth date etc) without the other person's consent&lt;br /&gt;
* Details of driver's license or Medicare cards (in fact, most government IDs are problematic in this regard)&lt;br /&gt;
&lt;br /&gt;
These systems are also fairly weak when it comes to close friends or family emulating that person. For example, many families are aware of the first holiday location, what color house a person lived in, pets names, etc. &lt;br /&gt;
&lt;br /&gt;
The only class of questions which are &amp;quot;safe&amp;quot; whilst being open are abstract questions, such as &amp;quot;what is your favorite shape?&amp;quot; and so on, which can be just as difficult to remember as a real password. &lt;br /&gt;
&lt;br /&gt;
A safe alternative to questions and answers is SMSing a random reset code or temporary password to the user's mobile phone. This costs about $0.10 c per reset, and is hard to obviate as it's a second factor and does not generally involve the Internet. Therefore it is hard for an attacker to intercept today. &lt;br /&gt;
&lt;br /&gt;
==Referer Checks==&lt;br /&gt;
&lt;br /&gt;
Referers is a client provided, optional HTTP header field, and as such can be completely faked. The referer field should not be used. If code contains this string:&lt;br /&gt;
&lt;br /&gt;
$_SERVER[&amp;quot;HTTP_REFERER&amp;quot;]&lt;br /&gt;
&lt;br /&gt;
the code is immediately suspect and should be inspected to ensure that no actual security decisions are made. If in doubt, completely remove this code. &lt;br /&gt;
&lt;br /&gt;
=Further Reading=&lt;br /&gt;
&lt;br /&gt;
[[PHP Security for Developers]]&lt;br /&gt;
[[Category:OWASP PHP Project]]&lt;/div&gt;</summary>
		<author><name>Vanderaj</name></author>	</entry>

	</feed>