RE: [PHP] Crypt
| From: | Krznaric Michael | Date: | Mon, 23 Oct 2000 13:09:57 +0000 |
| Subject: | RE: [PHP] Crypt | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-21785@lists.php.net to get a copy of this message | ||
The first two characters of every password are the salt for that
password. So when you retrieve the encrypted password from the database,
get the first two characters of the encrypted password and use those as the
salt when encryptying the user entered password.
Mike
-----Original Message-----
From: David Robley [mailto:huntsman@hermes.nisu.flinders.edu.au]
Sent: Monday, October 23, 2000 4:05 AM
To: Joseph H Blythe; PHP-General
Subject: Re: [PHP] Crypt
On Mon, 23 Oct 2000, Joseph H Blythe wrote:
> Hey,
>
> I was just trying to encrypt a user inputted password from a form field:
>
> $password = crypt($password);
>
> I then inserted it into the database, then when a user logs in I am
> basically comparing the users password encrypted to the one in the
> database, I have done this before but can't remember if I actually used
> the crypt function ( might have been md5 ) and for the life of me I
> can't find the code I wrote.
>
> The problem is that when I use the crypt function it keeps creating
> different encrypted strings from the same password.
>
> What am I doing wrong?
>
> Regards,
>
> Joseph
I think you might need a pinch of salt :-) Pass a salt value to crypt or
you'll get random salts, hence random values for the same input.
--
David Robley | WEBMASTER & Mail List Admin
RESEARCH CENTRE FOR INJURY STUDIES | http://www.nisu.flinders.edu.au/
AusEinet | http://auseinet.flinders.edu.au/
Flinders University, ADELAIDE, SOUTH AUSTRALIA
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net