Re: strange crypt() problem
| From: | Don Read | Date: | Fri, 20 Jun 2003 16:46:28 +0000 |
| Subject: | Re: strange crypt() problem | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-152320@lists.php.net to get a copy of this message | ||
On 19-Jun-2003 Huzz wrote:
> I have this bit of code to crypt user password in user registration as
> shown
> below.
>
> $cryptpass=crypt($makepass);
> which generated crypted password like eg 37Q9fppLHc4fQ with php 4.0
>
> And am using the codes below to check for valid login..
> // $pass - from login page
> // $dbpass - from the database
> $pass=crypt($pass,substr($dbpass,0,2));
> }
> if (strcmp($dbpass,$pass)) {
> return(0);
> }
>
>
> Recently i have moved the same file to a new server with php 4.3.1 the
> problem is the same piece of codes above generates completely differen
> crypted value eg.$1$RjZHv7qx$h/L9ZUNT48rilHB6fGoMP/ .. hence the login
> codes above does not work... :(
>
The '$1$' means it's a md5 password.
Don't chop-up the encryped passwd.
Use the whole string for the seed and let crypt() handle it:
$epass=crypt($pass, $dbpass);
if (strcmp($dbpass,$epass)) {
...
Regards,
--
Don Read dread@texas.net
-- It's always darkest before the dawn. So if you are going to
steal the neighbor's newspaper, that's the time to do it.
(53kr33t w0rdz: sql table query)