RE: [PHP-DB] MySQL password problem

From: Date: Tue, 16 Oct 2001 15:42:07 +0000
Subject: RE: [PHP-DB] MySQL password problem
Groups: php.db 
Request: Send a blank email to php-db+get-13372@lists.php.net to get a copy of this message
If your password was hashed when inserting record, then you should get NOTHING if you search with an unhashed password. Dump your table; I think you'll find your passwords (PW) are plain text. -----Original Message----- From: Eric Kilgore [mailto:kilgore@teleport.com] Sent: Tuesday, October 16, 2001 10:41 AM To: php-db@lists.php.net Subject: Re: [PHP-DB] MySQL password problem Yes, the password was hashed. I did this both from a php insert script and within a MySQL admin program to double check the hash. The field is called PW, upper case. The query doesn't return any rows. There are no errors. As I mentioned, if I remove the hashing (reentering the password as plain text in MySQL) and remove the function below so PW='$password' then the query returns the desired results, but as is, I get nothing. "Russ Michell" <r.j.michell@apu.ac.uk> wrote in message news:SIMEON.10110161603.B@k1c. anglia.ac.uk... > >$query = "select * FROM tblUsers WHERE UserID='$username' AND PW=PASSWORD('$password')"; > >$result = mysql_query($query, $conn); > > * Are you sure you 'PASSWORDED' (hashed) the password when you did the initial insert? > * Is the password filed in your DB called 'PW' (uppercase) or 'pw' (lowercase)?? > > Russ > > Do you get an error message or does the user you try to exctract seem not to exist? > > > On Tue, 16 Oct 2001 08:26:29 -0700 Eric Kilgore <kilgore@teleport.com> wrote: > > > Anyone have any ideas what is wrong with this query? I have been unable to > > get this to work with the password function. > > > > It works if I change the password field in MySQL to unencrypted text and > > remove the password function from this query but fails when the data is > > encrypted. > > > > Any help would be appreciated. > > > > $query = "select * FROM tblUsers WHERE UserID='$username' AND > > PW=PASSWORD('$password')"; > > $result = mysql_query($query, $conn); > > > > > > Eric Kilgore > > > > > > > > -- > > PHP Database Mailing List (http://www.php.net/) > > To unsubscribe, e-mail: php-db-unsubscribe@lists.php.net > > For additional commands, e-mail: php-db-help@lists.php.net > > To contact the list administrators, e-mail: php-list-admin@lists.php.net > > > > #-------------------------------------------------------# > > "Believe nothing - consider everything" > > Russ Michell > Anglia Polytechnic University Webteam > Room 1C 'The Eastings' East Road, Cambridge > > e: r.j.michell@apu.ac.uk > w: www.apu.ac.uk/webteam > > www.theruss.com > > #-------------------------------------------------------# > -- PHP Database Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-db-unsubscribe@lists.php.net For additional commands, e-mail: php-db-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.db (#13372) next »