Re: Crypt
| From: | Hardy Merrill | Date: | Thu, 26 Oct 2000 11:52:45 +0000 |
| Subject: | Re: Crypt | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-22113@lists.php.net to get a copy of this message | ||
Joseph H Blythe [joe.blythe@binarylogic.com.au] wrote:
> Krznaric Michael wrote:
>
> > The first two characters of every password are the salt for that
> > password. So when you retrieve the encrypted password from the database,
> > get the first two characters of the encrypted password and use those as the
> > salt when encryptying the user entered password.
> >
>
> Hey,
>
> Thanks to all who replied, so let me get this straight.
>
> A user joins up to my service, he/she enters a username and password, which is
> stored in the database the password is encrypted:
>
> $password = crypt($password);
>
> when the user logs in (the inputed password stored in $password) I retrieve
> the password from the database (stored in $pwd) and get the first two
> characters:
>
> $salt = substr($pwd, 0, 1);
I think you want 2 as the 3rd parameter to substr - you want
to pull out the 1st *2* characters from the currently encrypted
password to use as the salt for the unencrypted one.
>
> Now I will re-encrypt the inputed password and see if it matches the one in
> the database:
>
> $password = crypt($password, $salt);
>
> All looks well except when I try this the passwords are still different.
>
> Any ideas welcome,
>
> BTW: I tried md5 as well and this produced different results each time as well
>
> Regards,
>
> Joseph
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
--
Hardy Merrill
Mission Critical Linux, Inc.
http://www.missioncriticallinux.com