【问题标题】:Verification link not activating account验证链接未激活帐户
【发布时间】:2013-01-31 10:47:48
【问题描述】:

所以我在注册后发送了一个链接来验证一个帐户,该链接包含用户的电子邮件地址和一个 32 字符的代码,例如:

                $to      = $email;
                $subject = 'Signup | Verification';
                $message = '

                Thanks for signing up!
                Your account has been created, you can login with the following credentials after you have activated your account by pressing the url below.

                ------------------------
                Username: '.$username.'
                Password: '.$password.'
                ------------------------

                Please click this link to activate your account:
                localhost:8888/website/verify.php?email='.$email.'&hash='.$hash.'
                '; 

                $headers = 'From:myemail@email.com' . "\r\n"; 
                mail($to, $subject, $message, $headers); 

一切似乎都很好,我收到了带有这样链接的电子邮件:

http://localhost:8888/website/verify.php?email=myemail@email.com&hash=fe646d38bc2145ca6c3cf77d52820cd0

当我点击链接并尝试激活帐户时出现问题。我需要很好地验证.php,但我不断收到无效方法,我无法将验证设置为 1。

    <?php include "includes/base.php"; ?>

    <?php

        if(isset($_GET['Email']) && !empty($_GET['Email']) AND isset($_GET['Hash']) && !empty($_GET['Hash'])){
            $email = mysql_escape_string($_GET['Email']); 
            $hash = mysql_escape_string($_GET['Hash']); 
            $search = mysql_query("SELECT Email, Hash, Validation FROM users WHERE Email = '".$email."' AND Hash = '".$hash."' AND Validation = 0") or die(mysql_error()); 
            $match  = mysql_num_rows($search);


            if($match > 0){
                mysql_query("UPDATE users SET Validation = 1 WHERE Email = '".$email."' AND Hash = '".$hash."' AND Validation = 0") or die(mysql_error());
                echo "Your account has been activated, you can now login";
            }else{
                echo "The url is either invalid or you already have activated your account.";
            }

        }else{
            echo "Invalid approach, please use the link that has been sent to your email.";
        }


    ?>

【问题讨论】:

  • 您的代码有问题。 SQL 注入问题。
  • 我知道,这是我要整理的列表中的下一个。谢谢
  • 你的方法也有问题。切勿通过邮件发送密码(一次性密码除外,例如您的哈希)!为什么你一开始就知道密码?您应该(或最好必须)立即从提供的密码创建一个加盐哈希,存储这个并尽快忘记明文密码(从内存中擦除它,不要记录或存储任何内容)。其他事情:您的哈希是否包含秘密?您是否为此使用了安全算法?您的激活链接是否超时?

标签: php mysql


【解决方案1】:

1) 此代码不安全,因为它存在 SQL 注入问题。使用prepared statements 请记住,不再支持 mysql_* 函数,它们是depriated

2) 关于您的代码,我发现您的 GET 请求的“电子邮件”和“哈希”全部小写,但在 PHP 代码中您使用 $_GET['Email'] 和 $_GET['Hash']。 你需要改变这个:

 if(isset($_GET['Email']) && !empty($_GET['Email']) AND isset($_GET['Hash']) && !empty($_GET['Hash'])){
            $email = mysql_escape_string($_GET['Email']); 
            $hash = mysql_escape_string($_GET['Hash']); 

到这里

 if(isset($_GET['email']) && !empty($_GET['email']) AND isset($_GET['eash']) && !empty($_GET['eash'])){
            $email = mysql_escape_string($_GET['email']); 
            $hash = mysql_escape_string($_GET['eash']); 

或将您的 GET 请求更改为下一个:

http://localhost:8888/website/verify.php?Email=myemail@email.com&Hash=fe646d38bc2145ca6c3cf77d52820cd0

【讨论】:

【解决方案2】:

将Hash 更改为hash 和Email 更改为email。 (大写,但不在您发送的链接中)

此外,您的代码容易受到 sql 注入攻击,因为您直接使用 url 中的值来查询数据库。请使用mysql_real_escape_string 并在进行查询之前执行一些健全性检查。

【讨论】:

    【解决方案3】:

    PHP 中有大写字母,而链接中没有大写字母

    $_GET['Email']
    
    verify.php?email=myemail@email.com
    

    【讨论】:

      猜你喜欢
      • 2014-08-17
      • 2020-03-27
      • 2017-06-22
      • 1970-01-01
      • 1970-01-01
      • 2013-01-15
      • 1970-01-01
      • 2019-03-06
      • 1970-01-01
      相关资源
      最近更新 更多