Re: Crypt
| From: | Joseph H Blythe | Date: | Tue, 24 Oct 2000 00:43:00 +0000 |
| Subject: | Re: Crypt | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-21850@lists.php.net to get a copy of this message | ||
Krznaric Michael wrote:
> The first two characters of every password are the salt for that
> password. So when you retrieve the encrypted password from the database,
> get the first two characters of the encrypted password and use those as the
> salt when encryptying the user entered password.
>
Hey,
Thanks to all who replied, so let me get this straight.
A user joins up to my service, he/she enters a username and password, which is
stored in the database the password is encrypted:
$password = crypt($password);
when the user logs in (the inputed password stored in $password) I retrieve
the password from the database (stored in $pwd) and get the first two
characters:
$salt = substr($pwd, 0, 1);
Now I will re-encrypt the inputed password and see if it matches the one in
the database:
$password = crypt($password, $salt);
All looks well except when I try this the passwords are still different.
Any ideas welcome,
BTW: I tried md5 as well and this produced different results each time as well
Regards,
Joseph