Re: MySQL password problem
| From: | Russ Michell | Date: | Thu, 01 Jan 1970 00:00:00 +0000 |
| Subject: | Re: MySQL password problem | ||
| References: | 1 | Groups: | php.db |
| Request: | Send a blank email to php-db+get-13375@lists.php.net to get a copy of this message | ||
Not a problem.
Glad you sorted it!
Russ
On Tue, 16 Oct 2001 08:58:49 -0700 Eric Kilgore <kilgore@teleport.com> wrote:
> It was the field length, Russ, thanks.
>
> I had set the PW field length to 12, not realizing the hash length was 16.
>
> problem solved.
>
> Thanks for the help.
>
> Eric
>
> "Russ Michell" <r.j.michell@apu.ac.uk> wrote in message
> news:SIMEON.10110161627.E@k1c. anglia.ac.uk...
> > >If your password was hashed when inserting record, then you should get
> NOTHING if you search with
> > >an unhashed password.
> >
> > yeah but he re-did it:
> > re:
> >
> > "As I mentioned, if I remove the hashing (reentering the password as plain
> > text in MySQL) and remove the function below so PW='$password' then the
> > query returns the desired results, but as is, I get nothing."
> >
> >
> > Russ
> >
> > --- Begin Forwarded Message ---
> > Date: Tue, 16 Oct 2001 10:42:07 -0500
> > From: Rick Emery <remery@excel.com>
> > Subject: RE: [PHP-DB] MySQL password problem
> > Sender: php-db-return-13372-r.j.michell=anglia.ac.uk@lists.php.net
> > To: php-db@lists.php.net
> >
> > Reply-To: Rick Emery <remery@excel.com>
> > Message-ID:
> <EAA093B474ABD311A71E00508B5FE08305C2CAAB@adntex03.us.excel.com>
> >
> >
> > If your password was hashed when inserting record, then you should get
> > NOTHING if you search with an unhashed password.
> >
> > Dump your table; I think you'll find your passwords (PW) are plain text.
> >
> > -----Original Message-----
> > From: Eric Kilgore [mailto:kilgore@teleport.com]
> > Sent: Tuesday, October 16, 2001 10:41 AM
> > To: php-db@lists.php.net
> > Subject: Re: [PHP-DB] MySQL password problem
> >
> >
> > Yes, the password was hashed. I did this both from a php insert script and
> > within a MySQL admin program to double check the hash.
> > The field is called PW, upper case.
> > The query doesn't return any rows.
> > There are no errors.
> >
> > As I mentioned, if I remove the hashing (reentering the password as plain
> > text in MySQL) and remove the function below so PW='$password' then the
> > query returns the desired results, but as is, I get nothing.
> >
> > "Russ Michell" <r.j.michell@apu.ac.uk> wrote in message
> > news:SIMEON.10110161603.B@k1c. anglia.ac.uk...
> > > >$query = "select * FROM tblUsers WHERE UserID='$username' AND
> > PW=PASSWORD('$password')";
> > > >$result = mysql_query($query, $conn);
> > >
> > > * Are you sure you 'PASSWORDED' (hashed) the password when you did the
> > initial insert?
> > > * Is the password filed in your DB called 'PW' (uppercase) or
> > > 'pw'
> > (lowercase)??
> > >
> > > Russ
> > >
> > > Do you get an error message or does the user you try to exctract seem
> not
> > to exist?
> > >
> > >
> > > On Tue, 16 Oct 2001 08:26:29 -0700 Eric Kilgore <kilgore@teleport.com>
> > wrote:
> > >
> > > > Anyone have any ideas what is wrong with this query? I have been
> unable
> > to
> > > > get this to work with the password function.
> > > >
> > > > It works if I change the password field in MySQL to unencrypted text
> and
> > > > remove the password function from this query but fails when the data
> is
> > > > encrypted.
> > > >
> > > > Any help would be appreciated.
> > > >
> > > > $query = "select * FROM tblUsers WHERE UserID='$username' AND
> > > > PW=PASSWORD('$password')";
> > > > $result = mysql_query($query, $conn);
> > > >
> > > >
> > > > Eric Kilgore
> > > >
> > > >
> > > >
> > > > --
> > > > PHP Database Mailing List (http://www.php.net/)
> > > > To unsubscribe, e-mail: php-db-unsubscribe@lists.php.net
> > > > For additional commands, e-mail: php-db-help@lists.php.net
> > > > To contact the list administrators, e-mail:
> php-list-admin@lists.php.net
> > > >
> > >
> > > #-------------------------------------------------------#
> > >
> > > "Believe nothing - consider everything"
> > >
> > > Russ Michell
> > > Anglia Polytechnic University Webteam
> > > Room 1C 'The Eastings' East Road, Cambridge
> > >
> > > e: r.j.michell@apu.ac.uk
> > > w: www.apu.ac.uk/webteam
> > >
> > > www.theruss.com
> > >
> > > #-------------------------------------------------------#
> > >
> >
> >
> >
> > --
> > PHP Database Mailing List (http://www.php.net/)
> > To unsubscribe, e-mail: php-db-unsubscribe@lists.php.net
> > For additional commands, e-mail: php-db-help@lists.php.net
> > To contact the list administrators, e-mail: php-list-admin@lists.php.net
> >
> >
> > --
> > PHP Database Mailing List (http://www.php.net/)
> > To unsubscribe, e-mail: php-db-unsubscribe@lists.php.net
> > For additional commands, e-mail: php-db-help@lists.php.net
> > To contact the list administrators, e-mail: php-list-admin@lists.php.net
> >
> > --- End Forwarded Message ---
> >
> >
> > #-------------------------------------------------------#
> >
> > "Believe nothing - consider everything"
> >
> > Russ Michell
> > Anglia Polytechnic University Webteam
> > Room 1C 'The Eastings' East Road, Cambridge
> >
> > e: r.j.michell@apu.ac.uk
> > w: www.apu.ac.uk/webteam
> >
> > www.theruss.com
> >
> > #-------------------------------------------------------#
> >
>
>
>
> --
> PHP Database Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-db-unsubscribe@lists.php.net
> For additional commands, e-mail: php-db-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
#-------------------------------------------------------#
"Believe nothing - consider everything"
Russ Michell
Anglia Polytechnic University Webteam
Room 1C 'The Eastings' East Road, Cambridge
e: r.j.michell@apu.ac.uk
w: www.apu.ac.uk/webteam
www.theruss.com
#-------------------------------------------------------#