RE: [PHP] DES to MD5 password compare script

From: Date: Tue, 05 Sep 2000 21:09:02 +0000
Subject: RE: [PHP] DES to MD5 password compare script
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-15382@lists.php.net to get a copy of this message
> -----Original Message----- > From: kris@grinz.com [mailto:kris@grinz.com] > Sent: Tuesday, September 05, 2000 3:31 PM > To: php-general@lists.php.net > Subject: [PHP] DES to MD5 password compare script > > > I wrote the following script which compares a login password with > what is stored in a database. Now I am trying to run it on a server > which uses MD5 instead of DES. What needs to be changed in > order for it to work on this new box? (went from linux to freebsd > basically.) Any help is greatly appreciated. I am obviously more > familiar with DES than MD5. Please help! :) Kris -(code below)- > > else{ > $data=pg_fetch_object($result, $row); > $realpass=$data->password; > $passlen=strlen($realpass); > $seed=substr($realpass, 0, 2); > $pass=substr($realpass, 2, $passlen); Change the '2' in the two previous lines to instead use PHP's CRYPT_SALT_LENGTH constant. (Or, if you want to just hard-code a value, make it '12'.) > $loginpass=crypt($PHP_AUTH_PW, $seed); > $comparelen=strlen($loginpass); > $comparepass=substr($loginpass, 2, $comparelen); ...and, presumably, the same thing here. > if($comparepass != $pass){ > Header("WWW-Authenticate: Basic realm=\"PHLINK > ADMIN\""); > Header("HTTP/1.0 401 Unauthorized"); > $success=0; > } > else{$success=1;} > } --- Mark Roedel | "Blessed is he who has learned to laugh Systems Programmer | at himself, for he shall never cease LeTourneau University | to be entertained." Longview, Texas, USA | -- John Powell

« previous php.general (#15382) next »