Re: crypt() problems..help!
| From: | Teodor Cimpoesu | Date: | Mon, 25 Sep 2000 07:31:26 +0000 |
| Subject: | Re: crypt() problems..help! | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-17415@lists.php.net to get a copy of this message | ||
Hi Chad!
On Wed, 20 Sep 2000, Chad Day wrote:
> I have encrypted pw's stored in my database for my users.. it turns out that
> they can leave up to 2 characters off the password, or add seemingly any
> number of characters AFTER their password, and the encrypted values will
> match, and they will be allowed access.
>
> Example: user joe has password qwertyuiop
> joe can enter:
>
> qwertyui
.........^ 8th char. crypt() uses 8c/password and 2 as salt.
Don't like it? Use MD5() hash. You can feed in a 1G file as
a password and get same 32chars (128bits)
-- teodor