RE: [PHP-DB] MySQL password problem
| From: | Rick Emery | Date: | Tue, 16 Oct 2001 15:42:07 +0000 |
| Subject: | RE: [PHP-DB] MySQL password problem | ||
| Groups: | php.db | ||
| Request: | Send a blank email to php-db+get-13372@lists.php.net to get a copy of this message | ||
If your password was hashed when inserting record, then you should get
NOTHING if you search with an unhashed password.
Dump your table; I think you'll find your passwords (PW) are plain text.
-----Original Message-----
From: Eric Kilgore [mailto:kilgore@teleport.com]
Sent: Tuesday, October 16, 2001 10:41 AM
To: php-db@lists.php.net
Subject: Re: [PHP-DB] MySQL password problem
Yes, the password was hashed. I did this both from a php insert script and
within a MySQL admin program to double check the hash.
The field is called PW, upper case.
The query doesn't return any rows.
There are no errors.
As I mentioned, if I remove the hashing (reentering the password as plain
text in MySQL) and remove the function below so PW='$password' then the
query returns the desired results, but as is, I get nothing.
"Russ Michell" <r.j.michell@apu.ac.uk> wrote in message
news:SIMEON.10110161603.B@k1c. anglia.ac.uk...
> >$query = "select * FROM tblUsers WHERE UserID='$username' AND
PW=PASSWORD('$password')";
> >$result = mysql_query($query, $conn);
>
> * Are you sure you 'PASSWORDED' (hashed) the password when you did the
initial insert?
> * Is the password filed in your DB called 'PW' (uppercase) or 'pw'
(lowercase)??
>
> Russ
>
> Do you get an error message or does the user you try to exctract seem not
to exist?
>
>
> On Tue, 16 Oct 2001 08:26:29 -0700 Eric Kilgore <kilgore@teleport.com>
wrote:
>
> > Anyone have any ideas what is wrong with this query? I have been unable
to
> > get this to work with the password function.
> >
> > It works if I change the password field in MySQL to unencrypted text and
> > remove the password function from this query but fails when the data is
> > encrypted.
> >
> > Any help would be appreciated.
> >
> > $query = "select * FROM tblUsers WHERE UserID='$username' AND
> > PW=PASSWORD('$password')";
> > $result = mysql_query($query, $conn);
> >
> >
> > Eric Kilgore
> >
> >
> >
> > --
> > PHP Database Mailing List (http://www.php.net/)
> > To unsubscribe, e-mail: php-db-unsubscribe@lists.php.net
> > For additional commands, e-mail: php-db-help@lists.php.net
> > To contact the list administrators, e-mail: php-list-admin@lists.php.net
> >
>
> #-------------------------------------------------------#
>
> "Believe nothing - consider everything"
>
> Russ Michell
> Anglia Polytechnic University Webteam
> Room 1C 'The Eastings' East Road, Cambridge
>
> e: r.j.michell@apu.ac.uk
> w: www.apu.ac.uk/webteam
>
> www.theruss.com
>
> #-------------------------------------------------------#
>
--
PHP Database Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-db-unsubscribe@lists.php.net
For additional commands, e-mail: php-db-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net