RE: [PHP] DES to MD5 password compare script

From: Date: Fri, 08 Sep 2000 16:02:35 +0000
Subject: RE: [PHP] DES to MD5 password compare script
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-15901@lists.php.net to get a copy of this message
> -----Original Message----- > From: kris@grinz.com [mailto:kris@grinz.com] > Sent: Friday, September 08, 2000 10:30 AM > To: Mark Roedel > Cc: php-general@lists.php.net > Subject: RE: [PHP] DES to MD5 password compare script > > > I changed my scripting to: > > /*$passwd = entered by user > $realpass = from SQL DB*/ > > $data=pg_fetch_object($result, $row); > $realpass=$data->passwd; > $passlen=strlen($realpass); > $seed=substr($realpass, 0, $CRYPT_SALT_LENGTH); > $pass=substr($realpass, $CRYPT_SALT_LENGTH, > $passlen); > $loginpass=crypt($passwd, $seed); > $comparelen=strlen($loginpass); > $comparepass=substr($loginpass, $CRYPT_SALT_LENGTH, > $comparelen); > if($comparepass != $pass){ > $success=0; > } > else{$success=1;} > > The main goal is to encrypt $passwd with the same seed used to > encrypt the md5 pass already stored in the database, then > compare them. I just dont understand how to determine what the > seed is of the originally encrypted $realpass. $CRYPT_SALT_LENGTH is a PHP constant which stores the length of the salt string used by the crypt() function on your system. (Thus, using that instead of a hard-coded number will allow your script to work regardless of whether the current system prefers DES or MD5.) Does that make sense to you? Or am I misunderstanding the question now? --- Mark Roedel | "Blessed is he who has learned to laugh Systems Programmer | at himself, for he shall never cease LeTourneau University | to be entertained." Longview, Texas, USA | -- John Powell

« previous php.general (#15901) next »