crypt() problems..help!
| From: | Chad Day | Date: | Wed, 20 Sep 2000 13:56:00 +0000 |
| Subject: | crypt() problems..help! | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-17277@lists.php.net to get a copy of this message | ||
I have encrypted pw's stored in my database for my users.. it turns out that
they can leave up to 2 characters off the password, or add seemingly any
number of characters AFTER their password, and the encrypted values will
match, and they will be allowed access.
Example: user joe has password qwertyuiop
joe can enter:
qwertyui
qwertyuio
qwertyuioplkjhgjhds
and all will match the encrypted value in the database.
The process I use to generate passwords is:
$PASSWORD = genpassword(10);
$CRYPTPW = crypt($PASSWORD, mysalthere);
--
function genpassword($length){
srand((double)microtime()*1000000);
$vowels = array("a", "e", "i", "o", "u");
$cons = array("b", "c", "d", "g", "h",
"j", "k", "l", "m", "n", "p",
"r", "s", "t", "u", "v", "w",
"tr",
"cr", "br", "fr", "th", "dr", "ch",
"ph", "wr", "st", "sp", "sw", "pr",
"sl", "cl");
$num_vowels = count($vowels);
$num_cons = count($cons);
for($i = 0; $i < $length; $i++){
$password .= $cons[rand(0, $num_cons - 1)] . $vowels[rand(0,
$num_vowels - 1)];
}
return substr($password, 0, $length);
}
--
and the code used to authenticate users..
$query = mysql_query("SELECT USERID from admin where USERNAME='$USERNAME'");
$PASSWORD = crypt($PASSWORD, mysalthere);
if ($row = mysql_fetch_array($query)) {
$USERID = $row["USERID"];
}
if (@$USERID && @$PASSWORD) {
$res = mysql_query("SELECT USERID FROM admin where
USERID='$USERID' AND PASSWORD='$PASSWORD'");
if ($row = mysql_fetch_array($res)) {
$verified_admin = $row["USERID"];
}
I checked the mysql db field.. it's a varchar of 20, which appears to be
long enough to store the value.
The password field in the form has no minimum length.
I echoed the output of $PASSWORD in the authenticate screen to make sure
that all of the encrypted values for those different passwords were coming
back .. they were, and they were all the same. I am totally stumped. Can
anyone help?
Chad Day
Beach Associates
When I speak german... I think german in my head... but like...Do skript
kiddies see a w40l3 8uncha 1's and 0's and 3's and 4's and 7's in their
h34d'5 w43n t43y R +a1k1n6 ? -- SirStanley