RE: [PHP] Password checking

From: Date: Tue, 05 Sep 2000 14:56:34 +0000
Subject: RE: [PHP] Password checking
Groups: php.general 
Request: Send a blank email to php-general+get-15305@lists.php.net to get a copy of this message
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 try: $sql = "SELECT username, password, PASSWD('$password') AS form_pass_enc FROM table WHERE user='$username'" $result = mysql_query($sql,$db); $row = mysql_fetch_array($result); and test to see if $row['password'] and $row['form_pass_enc'] are the same. Ollie - -------------------------------------------- Ollie Cook +44 (7946) 057 198 Programmer, Admin XCalibre Communications PGP: http://ollie.zenox.dhs.org/pgp-key #define QUESTION ((bb) || !(bb)) - -------------------------------------------- > -----Original Message----- > From: Wee Chua [mailto:Chua@mail.interclean.com] > Sent: 05 September 2000 15:36 > To: 'Krznaric Michael'; PHP (E-mail) > Subject: RE: [PHP] Password checking > > > Hi all, > I was wrong, the problem is still exist. The output of the passwords > different from the statement below, the first password from > Mysql display on > the screen is encrypted password, the second password is the > password what I > enter. How could I make it work? Please help? Thanks. > > -----Original Message----- > From: Krznaric Michael [mailto:mkrznaric@rand.com] > Sent: Tuesday, September 05, 2000 10:27 AM > To: 'Wee Chua'; Krznaric Michael; PHP (E-mail) > Subject: RE: [PHP] Password checking > > > Take it step by step; > > print "Row -> User: ".$row["user"]."<BR>"; > print "Row -> Password: ".$row["password"]."<BR>"; > print "Username: $username<BR>"; > print "Password: $password<BR>"; > > then if everything seems o.k. do the following, > > //This should either be true or false > print "First Equality: ". $row["user"]==$username."<BR>"; > print "Second Equality: ".$row["password"]) == > $password."<BR>"; > print "Third Equality: ".$username !=""."<BR>"; > > So each one of those should be true. Concentrate on the false one. > > Mike > > if (($row["user"] == $username) and (($row["password"]) == > $password) and > > ($username !="")) > > -----Original Message----- > From: Wee Chua [mailto:Chua@mail.interclean.com] > Sent: Tuesday, September 05, 2000 10:03 AM > To: 'Krznaric Michael'; PHP (E-mail) > Subject: RE: [PHP] Password checking > > > Yes, I tried everything from what Julie suggested me to change on the > statement. > > -----Original Message----- > From: Krznaric Michael [mailto:mkrznaric@rand.com] > Sent: Tuesday, September 05, 2000 10:15 AM > To: 'Wee Chua'; 'julie@thickbook.com'; PHP (E-mail) > Subject: RE: [PHP] Password checking > > > Did you try using && instead of "and"? > > Mike > > -----Original Message----- > From: Wee Chua [mailto:Chua@mail.interclean.com] > Sent: Tuesday, September 05, 2000 9:51 AM > To: 'julie@thickbook.com'; MySQL (E-mail); PHP (E-mail) > Subject: RE: [PHP] Password checking > > > Hi Julie and all, > I tried your solution but it is still not working. I tried to > take away > ($row["password"] == "$password") and rest works fine. I > don't what is > wrong with my ($row["password"] == "$password") statement, > please help! > Thanks in advance. > > Calvin > > -----Original Message----- > From: Julie Meloni [mailto:julie@thickbook.com] > Sent: Tuesday, September 05, 2000 9:59 AM > To: Wee Chua > Cc: MySQL (E-mail); PHP (E-mail) > Subject: Re: [PHP] Password checking > > > > > if (($row["user"] == $username) and (($row["password"]) == > $password) and > > ($username !="")) > > Try: > > if (($row["user"] == "$username") && ($row["password"] == > > "$password") > && ($username != "")) > > > - julie > > +------------------------------------------------+ > | Julie Meloni (jcm@i2ii.com) | > | Tech. Director, i2i Interactive (www.i2ii.com) | > | | > | "PHP Essentials" & "PHP Fast & Easy" | > | http://www.thickbook.com/ | > +------------------------------------------------+ > > > -- > --------------------------------------------------------------------- > Please check "http://www.mysql.com/php/manual.php" > before > posting. To request this thread, e-mail > mysql-thread49757@lists.mysql.com > > To unsubscribe, send a message to: > <mysql-unsubscribe-Chua=mail.interclean.com@lists.mysql.com> > > If you have a broken mail client that cannot send a message > to the above > address(Microsoft Outlook), you can use > http://lists.mysql.com/php/unsubscribe.php > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: > php-list-admin@lists.php.net > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: > php-list-admin@lists.php.net > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: > php-list-admin@lists.php.net > -----BEGIN PGP SIGNATURE----- Version: PGPfreeware 6.5.8 for non-commercial use <http://www.pgp.com> iQA/AwUBObUJosPaWaNT0pVnEQLFMgCdF2P8nh/PJgkEBV1XSIxpp+KWfuUAn2vy mKfOGKqzKNBRrvjnJUVFXsjM =p8uF -----END PGP SIGNATURE-----

« previous php.general (#15305) next »