Re: crypt() problems..help!
| From: | Jason Granum | Date: | Sun, 24 Sep 2000 21:32:19 +0000 |
| Subject: | Re: crypt() problems..help! | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-19633@lists.php.net to get a copy of this message | ||
Aren't passwords limited to 8 characters? Not sure. But that could be
id. The password joe has is 10 characters long, so from how I recall the
crypt will chop off the last 2 letters and thats his real password,
anything additional is chopped off, thus making the 8 letter version of
his pasword work, as well as a 12 letter version.
I could be wrong, but this could be something to concider.
On Wed, 20 Sep 2000, Chad Day wrote:
> I have encrypted pw's stored in my database for my users.. it turns out that
> they can leave up to 2 characters off the password, or add seemingly any
> number of characters AFTER their password, and the encrypted values will
> match, and they will be allowed access.
>
> Example: user joe has password qwertyuiop
> joe can enter:
>
> qwertyui
> qwertyuio
> qwertyuioplkjhgjhds
>
> and all will match the encrypted value in the database.
>
> The process I use to generate passwords is:
>
> $PASSWORD = genpassword(10);
> $CRYPTPW = crypt($PASSWORD, mysalthere);
>
> --
>
>
> function genpassword($length){
>
> srand((double)microtime()*1000000);
>
> $vowels = array("a", "e", "i", "o", "u");
> $cons = array("b", "c", "d", "g", "h",
> "j", "k", "l", "m", "n", "p",
> "r", "s", "t", "u", "v", "w",
> "tr",
> "cr", "br", "fr", "th", "dr",
> "ch", "ph", "wr", "st", "sp", "sw",
> "pr",
> "sl", "cl");
>
> $num_vowels = count($vowels);
> $num_cons = count($cons);
>
> for($i = 0; $i < $length; $i++){
> $password .= $cons[rand(0, $num_cons - 1)] . $vowels[rand(0,
> $num_vowels - 1)];
> }
>
> return substr($password, 0, $length);
> }
>
> --
>
> and the code used to authenticate users..
>
> $query = mysql_query("SELECT USERID from admin where
> USERNAME='$USERNAME'");
>
> $PASSWORD = crypt($PASSWORD, mysalthere);
> if ($row = mysql_fetch_array($query)) {
> $USERID = $row["USERID"];
> }
>
> if (@$USERID && @$PASSWORD) {
> $res = mysql_query("SELECT USERID FROM admin where
> USERID='$USERID' AND PASSWORD='$PASSWORD'");
> if ($row = mysql_fetch_array($res)) {
> $verified_admin = $row["USERID"];
> }
>
>
> I checked the mysql db field.. it's a varchar of 20, which appears to be
> long enough to store the value.
> The password field in the form has no minimum length.
>
> I echoed the output of $PASSWORD in the authenticate screen to make sure
> that all of the encrypted values for those different passwords were coming
> back .. they were, and they were all the same. I am totally stumped. Can
> anyone help?
>
> Chad Day
> Beach Associates
>
> When I speak german... I think german in my head... but like...Do skript
> kiddies see a w40l3 8uncha 1's and 0's and 3's and 4's and 7's in
> their
> h34d'5 w43n t43y R +a1k1n6 ? -- SirStanley
>
>
>