The following warnings occurred:
Warning [2] Undefined variable $unreadreports - Line: 26 - File: global.php(961) : eval()'d code PHP 8.2.25 (Linux)
File Line Function
/global.php(961) : eval()'d code 26 errorHandler->error
/global.php 961 eval
/showthread.php 28 require_once





× This forum is read only. As of July 23, 2019, the UserSpice forums have been closed. To receive support, please join our Discord by clicking here. Thank you!

  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Multiple Forms
#9
argh i see, i'll give that ago, defo gonna look at the token class a little closer, i noticed its using
md5( uniqid() ) so I've changed the class a little,

currently it generates: `<input type="hidden" name="csrf" value="89f378ee3aa6812ace51c50ce5f24e8b">'

but if we change class to:

`class Token {
public static function generate(){
if (function_exists('mcrypt_create_iv')) { //checks if exists as deprecated from php7.1.0
return Session::put(Config::get('session/token_name'), bin2hex(mcrypt_create_iv(32, MCRYPT_DEV_URANDOM)) );
} else {
return Session::put(Config::get('session/token_name'), bin2hex(openssl_random_pseudo_bytes(32)) );
}
}

public static function check($token){
$tokenName = Config::get('session/token_name');

if (Session::exists($tokenName) && $token === Session::get($tokenName)) {
Session::delete($tokenName);
return true;
}
return false;
}
}
'

it generates:
Code:
<input type="hidden" name="csrf" value="d400c97e10082978da1541ba27b3f4501d796116a2d466e49740038d30d56883">


which is far less predictable than uniqid()
  Reply


Messages In This Thread
Multiple Forms - by Brandin - 06-25-2017, 12:54 PM
Multiple Forms - by faguss - 07-14-2017, 10:26 PM
Multiple Forms - by firestorm - 07-15-2017, 06:56 AM
Multiple Forms - by firestorm - 07-15-2017, 06:57 AM
Multiple Forms - by firestorm - 07-15-2017, 11:20 AM
Multiple Forms - by karsen - 07-15-2017, 02:56 PM
Multiple Forms - by firestorm - 07-15-2017, 03:11 PM
Multiple Forms - by karsen - 07-15-2017, 04:33 PM
Multiple Forms - by firestorm - 07-15-2017, 04:45 PM
Multiple Forms - by karsen - 07-15-2017, 04:56 PM
Multiple Forms - by firestorm - 07-15-2017, 05:29 PM
Multiple Forms - by karsen - 07-15-2017, 06:03 PM
Multiple Forms - by firestorm - 07-15-2017, 07:17 PM
Multiple Forms - by bladerunner - 12-14-2017, 11:51 AM

Forum Jump:


Users browsing this thread: 2 Guest(s)