RE: [PHP] DES to MD5 password compare script
| From: | Mark Roedel | Date: | Tue, 05 Sep 2000 21:09:02 +0000 |
| Subject: | RE: [PHP] DES to MD5 password compare script | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-15382@lists.php.net to get a copy of this message | ||
> -----Original Message-----
> From: kris@grinz.com [mailto:kris@grinz.com]
> Sent: Tuesday, September 05, 2000 3:31 PM
> To: php-general@lists.php.net
> Subject: [PHP] DES to MD5 password compare script
>
>
> I wrote the following script which compares a login password with
> what is stored in a database. Now I am trying to run it on a server
> which uses MD5 instead of DES. What needs to be changed in
> order for it to work on this new box? (went from linux to freebsd
> basically.) Any help is greatly appreciated. I am obviously more
> familiar with DES than MD5. Please help! :) Kris -(code below)-
>
> else{
> $data=pg_fetch_object($result, $row);
> $realpass=$data->password;
> $passlen=strlen($realpass);
> $seed=substr($realpass, 0, 2);
> $pass=substr($realpass, 2, $passlen);
Change the '2' in the two previous lines to instead use PHP's
CRYPT_SALT_LENGTH constant. (Or, if you want to just hard-code a value,
make it '12'.)
> $loginpass=crypt($PHP_AUTH_PW, $seed);
> $comparelen=strlen($loginpass);
> $comparepass=substr($loginpass, 2, $comparelen);
...and, presumably, the same thing here.
> if($comparepass != $pass){
> Header("WWW-Authenticate: Basic realm=\"PHLINK
> ADMIN\"");
> Header("HTTP/1.0 401 Unauthorized");
> $success=0;
> }
> else{$success=1;}
> }
---
Mark Roedel | "Blessed is he who has learned to laugh
Systems Programmer | at himself, for he shall never cease
LeTourneau University | to be entertained."
Longview, Texas, USA | -- John Powell