Re: crypt() problems..help!

From: Date: Mon, 25 Sep 2000 07:31:26 +0000
Subject: Re: crypt() problems..help!
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-17415@lists.php.net to get a copy of this message
Hi Chad! On Wed, 20 Sep 2000, Chad Day wrote: > I have encrypted pw's stored in my database for my users.. it turns out that > they can leave up to 2 characters off the password, or add seemingly any > number of characters AFTER their password, and the encrypted values will > match, and they will be allowed access. > > Example: user joe has password qwertyuiop > joe can enter: > > qwertyui .........^ 8th char. crypt() uses 8c/password and 2 as salt. Don't like it? Use MD5() hash. You can feed in a 1G file as a password and get same 32chars (128bits) -- teodor

« previous php.general (#17415) next »