RE: [PHP] DES to MD5 password compare script

From: Date: Fri, 08 Sep 2000 15:29:40 +0000
Subject: RE: [PHP] DES to MD5 password compare script
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-15897@lists.php.net to get a copy of this message
I changed my scripting to: /*$passwd = entered by user $realpass = from SQL DB*/ $data=pg_fetch_object($result, $row); $realpass=$data->passwd; $passlen=strlen($realpass); $seed=substr($realpass, 0, $CRYPT_SALT_LENGTH); $pass=substr($realpass, $CRYPT_SALT_LENGTH, $passlen); $loginpass=crypt($passwd, $seed); $comparelen=strlen($loginpass); $comparepass=substr($loginpass, $CRYPT_SALT_LENGTH, $comparelen); if($comparepass != $pass){ $success=0; } else{$success=1;} The main goal is to encrypt $passwd with the same seed used to encrypt the md5 pass already stored in the database, then compare them. I just dont understand how to determine what the seed is of the originally encrypted $realpass. Any ideas? Kris On 5 Sep 00, at 16:09, Mark Roedel wrote: > > -----Original Message----- > > From: kris@grinz.com [mailto:kris@grinz.com] > > Sent: Tuesday, September 05, 2000 3:31 PM > > To: php-general@lists.php.net > > Subject: [PHP] DES to MD5 password compare script > > > > > > I wrote the following script which compares a login password with > > what is stored in a database. Now I am trying to run it on a server > > which uses MD5 instead of DES. What needs to be changed in > > order for it to work on this new box? (went from linux to freebsd > > basically.) Any help is greatly appreciated. I am obviously more > > familiar with DES than MD5. Please help! :) Kris -(code below)- > > > > else{ > > $data=pg_fetch_object($result, $row); > > $realpass=$data->password; > > $passlen=strlen($realpass); > > $seed=substr($realpass, 0, 2); > > $pass=substr($realpass, 2, $passlen); > > Change the '2' in the two previous lines to instead use PHP's > CRYPT_SALT_LENGTH constant. (Or, if you want to just hard-code a value, > make it '12'.) > > > $loginpass=crypt($PHP_AUTH_PW, $seed); > > $comparelen=strlen($loginpass); > > $comparepass=substr($loginpass, 2, $comparelen); > > ...and, presumably, the same thing here. > > > if($comparepass != $pass){ > > Header("WWW-Authenticate: Basic realm=\"PHLINK > > ADMIN\""); > > Header("HTTP/1.0 401 Unauthorized"); > > $success=0; > > } > > else{$success=1;} > > } > > > > --- > Mark Roedel | "Blessed is he who has learned to laugh > Systems Programmer | at himself, for he shall never cease > LeTourneau University | to be entertained." > Longview, Texas, USA | -- John Powell >

« previous php.general (#15897) next »