[FX.php List] [OFF] sending email confirmation
Roger Price
rp272 at cam.ac.uk
Tue Mar 4 08:40:00 MST 2008
Steve
Yes when you base64 encode '0001' you get the 'MDAwMQ=='
I have since looked at md5() and while it's just as easy to encode there does not appear to be a simple decode function.
I'm not quite so worried about security as this strategy would not in any case prevent malicious responses but it should limit them to only the very dedicated hacker and quite frankly I don't suppose they would be bothered!
Roger
----- Original Message -----
From: Steve Winter
To: 'FX.php Discussion List'
Sent: Tuesday, March 04, 2008 3:15 PM
Subject: RE: [FX.php List] [OFF] sending email confirmation
Hi Roger,
I presume that the presence of the two == are a function of base64_encode.?? If not, what purpose do they serve.?
Perhaps using an alternative encoding method (eg md5) might resolve the issue, since it would not result in == characters.??
Cheers
Steve
------------------------------------------------------------------------------
From: fx.php_list-bounces at mail.iviking.org [mailto:fx.php_list-bounces at mail.iviking.org] On Behalf Of Roger Price
Sent: 04 March 2008 15:10
To: FX.php Discussion List
Subject: [FX.php List] [OFF] sending email confirmation
As part of a web project I am collecting data from our some of our past students that we have lost contact with.
I want to try to ensure that we don't get too many malicious returns so I intend to send a confirmation to the entered email address with an activation link.
So far so good!
In order that the database record key is not blatantly obvious I'm using base64_encode!
however when I mail a link such as: http://www.xxx.xxx.xx.xx..edit2.html?rec=MDAwMQ==
the two '=' characters that are generated at the end of this particular record are omitted from the hyperlink when viewed in Outlook Express or Windows Mail. Entourage only omits one! However Outlook and my webmail program work perfectly.
If anybody resolved this problem before I would be grateful to know the best way.
Roger
------------------------------------------------------------------------------
_______________________________________________
FX.php_List mailing list
FX.php_List at mail.iviking.org
http://www.iviking.org/mailman/listinfo/fx.php_list
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://www.iviking.org/pipermail/fx.php_list/attachments/20080304/4bb54efd/attachment-0001.html
More information about the FX.php_List
mailing list