Alex Rivera | Logout

ASP.NET user login best practices

Asked 2008-09-30T10:07:40.267
9

I want to make a login system using ASP.NET (MVC).

On the internet, I found some bad examples that involved SQL in Click events. Other information pointed to the ASP.NET built-in membership provider.

However, I want to roll my own. I don't want to use the built-in membership provider, as it only seems to work on MS SQL, and I don't like the idea of having a few foreign tables in my database.

I could probably think of something, but I need a few pointers in the right direction. It does not have to be high-security, but just regular common-sense security.

And I have a few direct questions:

  1. A lot of systems seem to have the Session ID stored in a user table. I guess this is to tie a session to a user to prevent hijacking. Do check this every time a user enters a page? And what do I do if the session expires?

  2. Hashing, salting, what does it do? I know of MD5 hashing and I have used it before. But not salting.

  3. Best practices for cookies?

Edit
Report

1 Answer

2

Salting is the practice of adding a unqiue string of characters to whatever is being hashed. Suppose mySalt = abc123 and my password is passwd. In PHP, I would use hashResult = md5(mySalt + password).

Suppose the string is intercepted. You try to match the string, but you end up matching gibberish because the password was salted before encrypted. Just remember that whatever you use for salt must be continuous throughout the application. If you salt the password before storage, you must compare the hashed, salted password to the DB.

answered 2008-09-30T11:44:54.260

Your Answer