RE: [PHP] DES to MD5 password compare script
| From: | Mark Roedel | Date: | Fri, 08 Sep 2000 16:02:35 +0000 |
| Subject: | RE: [PHP] DES to MD5 password compare script | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-15901@lists.php.net to get a copy of this message | ||
> -----Original Message-----
> From: kris@grinz.com [mailto:kris@grinz.com]
> Sent: Friday, September 08, 2000 10:30 AM
> To: Mark Roedel
> Cc: php-general@lists.php.net
> Subject: RE: [PHP] DES to MD5 password compare script
>
>
> I changed my scripting to:
>
> /*$passwd = entered by user
> $realpass = from SQL DB*/
>
> $data=pg_fetch_object($result, $row);
> $realpass=$data->passwd;
> $passlen=strlen($realpass);
> $seed=substr($realpass, 0, $CRYPT_SALT_LENGTH);
> $pass=substr($realpass, $CRYPT_SALT_LENGTH,
> $passlen);
> $loginpass=crypt($passwd, $seed);
> $comparelen=strlen($loginpass);
> $comparepass=substr($loginpass, $CRYPT_SALT_LENGTH,
> $comparelen);
> if($comparepass != $pass){
> $success=0;
> }
> else{$success=1;}
>
> The main goal is to encrypt $passwd with the same seed used to
> encrypt the md5 pass already stored in the database, then
> compare them. I just dont understand how to determine what the
> seed is of the originally encrypted $realpass.
$CRYPT_SALT_LENGTH is a PHP constant which stores the length of the salt
string used by the crypt() function on your system. (Thus, using that
instead of a hard-coded number will allow your script to work regardless of
whether the current system prefers DES or MD5.)
Does that make sense to you? Or am I misunderstanding the question now?
---
Mark Roedel | "Blessed is he who has learned to laugh
Systems Programmer | at himself, for he shall never cease
LeTourneau University | to be entertained."
Longview, Texas, USA | -- John Powell