Re: crypt() problems..help!

From: Date: Sun, 24 Sep 2000 21:32:19 +0000
Subject: Re: crypt() problems..help!
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-19633@lists.php.net to get a copy of this message
Aren't passwords limited to 8 characters? Not sure. But that could be id. The password joe has is 10 characters long, so from how I recall the crypt will chop off the last 2 letters and thats his real password, anything additional is chopped off, thus making the 8 letter version of his pasword work, as well as a 12 letter version. I could be wrong, but this could be something to concider. On Wed, 20 Sep 2000, Chad Day wrote: > I have encrypted pw's stored in my database for my users.. it turns out that > they can leave up to 2 characters off the password, or add seemingly any > number of characters AFTER their password, and the encrypted values will > match, and they will be allowed access. > > Example: user joe has password qwertyuiop > joe can enter: > > qwertyui > qwertyuio > qwertyuioplkjhgjhds > > and all will match the encrypted value in the database. > > The process I use to generate passwords is: > > $PASSWORD = genpassword(10); > $CRYPTPW = crypt($PASSWORD, mysalthere); > > -- > > > function genpassword($length){ > > srand((double)microtime()*1000000); > > $vowels = array("a", "e", "i", "o", "u"); > $cons = array("b", "c", "d", "g", "h", > "j", "k", "l", "m", "n", "p", > "r", "s", "t", "u", "v", "w", > "tr", > "cr", "br", "fr", "th", "dr", > "ch", "ph", "wr", "st", "sp", "sw", > "pr", > "sl", "cl"); > > $num_vowels = count($vowels); > $num_cons = count($cons); > > for($i = 0; $i < $length; $i++){ > $password .= $cons[rand(0, $num_cons - 1)] . $vowels[rand(0, > $num_vowels - 1)]; > } > > return substr($password, 0, $length); > } > > -- > > and the code used to authenticate users.. > > $query = mysql_query("SELECT USERID from admin where > USERNAME='$USERNAME'"); > > $PASSWORD = crypt($PASSWORD, mysalthere); > if ($row = mysql_fetch_array($query)) { > $USERID = $row["USERID"]; > } > > if (@$USERID && @$PASSWORD) { > $res = mysql_query("SELECT USERID FROM admin where > USERID='$USERID' AND PASSWORD='$PASSWORD'"); > if ($row = mysql_fetch_array($res)) { > $verified_admin = $row["USERID"]; > } > > > I checked the mysql db field.. it's a varchar of 20, which appears to be > long enough to store the value. > The password field in the form has no minimum length. > > I echoed the output of $PASSWORD in the authenticate screen to make sure > that all of the encrypted values for those different passwords were coming > back .. they were, and they were all the same. I am totally stumped. Can > anyone help? > > Chad Day > Beach Associates > > When I speak german... I think german in my head... but like...Do skript > kiddies see a w40l3 8uncha 1's and 0's and 3's and 4's and 7's in > their > h34d'5 w43n t43y R +a1k1n6 ? -- SirStanley > > >

« previous php.general (#19633) next »