RE: [PHP] DES to MD5 password compare script
| From: | kris at grinz dot com | Date: | Fri, 08 Sep 2000 15:29:40 +0000 |
| Subject: | RE: [PHP] DES to MD5 password compare script | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-15897@lists.php.net to get a copy of this message | ||
I changed my scripting to:
/*$passwd = entered by user
$realpass = from SQL DB*/
$data=pg_fetch_object($result, $row);
$realpass=$data->passwd;
$passlen=strlen($realpass);
$seed=substr($realpass, 0, $CRYPT_SALT_LENGTH);
$pass=substr($realpass, $CRYPT_SALT_LENGTH,
$passlen);
$loginpass=crypt($passwd, $seed);
$comparelen=strlen($loginpass);
$comparepass=substr($loginpass, $CRYPT_SALT_LENGTH,
$comparelen);
if($comparepass != $pass){
$success=0;
}
else{$success=1;}
The main goal is to encrypt $passwd with the same seed used to
encrypt the md5 pass already stored in the database, then
compare them. I just dont understand how to determine what the
seed is of the originally encrypted $realpass.
Any ideas?
Kris
On 5 Sep 00, at 16:09, Mark Roedel wrote:
> > -----Original Message-----
> > From: kris@grinz.com [mailto:kris@grinz.com]
> > Sent: Tuesday, September 05, 2000 3:31 PM
> > To: php-general@lists.php.net
> > Subject: [PHP] DES to MD5 password compare script
> >
> >
> > I wrote the following script which compares a login password with
> > what is stored in a database. Now I am trying to run it on a server
> > which uses MD5 instead of DES. What needs to be changed in
> > order for it to work on this new box? (went from linux to freebsd
> > basically.) Any help is greatly appreciated. I am obviously more
> > familiar with DES than MD5. Please help! :) Kris -(code below)-
> >
> > else{
> > $data=pg_fetch_object($result, $row);
> > $realpass=$data->password;
> > $passlen=strlen($realpass);
> > $seed=substr($realpass, 0, 2);
> > $pass=substr($realpass, 2, $passlen);
>
> Change the '2' in the two previous lines to instead use PHP's
> CRYPT_SALT_LENGTH constant. (Or, if you want to just hard-code a value,
> make it '12'.)
>
> > $loginpass=crypt($PHP_AUTH_PW, $seed);
> > $comparelen=strlen($loginpass);
> > $comparepass=substr($loginpass, 2, $comparelen);
>
> ...and, presumably, the same thing here.
>
> > if($comparepass != $pass){
> > Header("WWW-Authenticate: Basic realm=\"PHLINK
> > ADMIN\"");
> > Header("HTTP/1.0 401 Unauthorized");
> > $success=0;
> > }
> > else{$success=1;}
> > }
>
>
>
> ---
> Mark Roedel | "Blessed is he who has learned to laugh
> Systems Programmer | at himself, for he shall never cease
> LeTourneau University | to be entertained."
> Longview, Texas, USA | -- John Powell
>