Authenticate User | Build User Login with PHP and MySQL | Part 4 | Mage Mastery

preview_player
Показать описание


Subscribe to this channel for more videos!

Рекомендации по теме
Комментарии
Автор

I think we should use general messages only. If you provide "No user exist", you are telling the attackers that this user doesn't exist in the database. If attackers have a list of existing users, they will only need to check the password

crazier
Автор

Max, why in the seven hells would you do something like this?? The newbies should learn best practices immediately! There is no such universe in which an application will have a plain text password. Teach the people how to insert a hash into the password field and how to verify it in the login procedure, among other things.

marebitomarebito
join shbcf.ru