RE: [PHP] DES to MD5 password compare script
| From: | kris at grinz dot com | Date: | Fri, 08 Sep 2000 16:24:02 +0000 |
| Subject: | RE: [PHP] DES to MD5 password compare script | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-15904@lists.php.net to get a copy of this message | ||
Reply at bottom..
On 8 Sep 00, at 11:02, Mark Roedel wrote:
> > -----Original Message-----
> > From: kris@grinz.com [mailto:kris@grinz.com]
> > Sent: Friday, September 08, 2000 10:30 AM
> > To: Mark Roedel
> > Cc: php-general@lists.php.net
> > Subject: RE: [PHP] DES to MD5 password compare script
> >
> >
> > I changed my scripting to:
> >
> > /*$passwd = entered by user
> > $realpass = from SQL DB*/
> >
> > $data=pg_fetch_object($result, $row);
> > $realpass=$data->passwd;
> > $passlen=strlen($realpass);
> > $seed=substr($realpass, 0, $CRYPT_SALT_LENGTH);
> > $pass=substr($realpass, $CRYPT_SALT_LENGTH,
> > $passlen);
> > $loginpass=crypt($passwd, $seed);
> > $comparelen=strlen($loginpass);
> > $comparepass=substr($loginpass, $CRYPT_SALT_LENGTH,
> > $comparelen);
> > if($comparepass != $pass){
> > $success=0;
> > }
> > else{$success=1;}
> >
> > The main goal is to encrypt $passwd with the same seed used to
> > encrypt the md5 pass already stored in the database, then
> > compare them. I just dont understand how to determine what the
> > seed is of the originally encrypted $realpass.
>
> $CRYPT_SALT_LENGTH is a PHP constant which stores the length of the salt
> string used by the crypt() function on your system. (Thus, using that
> instead of a hard-coded number will allow your script to work regardless of
> whether the current system prefers DES or MD5.)
>
> Does that make sense to you? Or am I misunderstanding the question now?
That makes sense. The problem I'm running into is that the script
above doesn't seem to be grabbing the salt from the pass stored in
db. My script is crypting $passwd with a new seed instead of using
the same seed used previously to crypt $realpass. Did I use
$CRYPT_SALT_LENGTH correctly in the updated version of the
script (above)? Here is a list of what should happen.
grab $realpass from database (works)
determine seed used when $realpass was crypted (doesn't work)
crypt $passwd with $realpass' seed (used to work when this was
on a box using DES)
compare and set $success(should work once seed problem is
fixed).
I am assuming you can use MD5 the same way DES can be used
to crypt a password, then compare the two encrypted for a match.
Thanks for your help. Looking forward to your reply.
Kris