Re: Crypt
| From: | Joseph H Blythe | Date: | Thu, 26 Oct 2000 22:26:18 +0000 |
| Subject: | Re: Crypt | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-22232@lists.php.net to get a copy of this message | ||
Hardy Merrill wrote:
> Joseph H Blythe [joe.blythe@binarylogic.com.au] wrote:
> > Krznaric Michael wrote:
> >
> > > The first two characters of every password are the salt for that
> > > password. So when you retrieve the encrypted password from the database,
> > > get the first two characters of the encrypted password and use those as the
> > > salt when encryptying the user entered password.
> > >
> >
> > Hey,
> >
> > Thanks to all who replied, so let me get this straight.
> >
> > A user joins up to my service, he/she enters a username and password, which is
> > stored in the database the password is encrypted:
> >
> > $password = crypt($password);
> >
> > when the user logs in (the inputed password stored in $password) I retrieve
> > the password from the database (stored in $pwd) and get the first two
> > characters:
> >
> > $salt = substr($pwd, 0, 1);
>
> I think you want 2 as the 3rd parameter to substr - you want
> to pull out the 1st *2* characters from the currently encrypted
> password to use as the salt for the unencrypted one.
Sorry It is a typo, it should be 2, netherless I still get different results
evertime I crypt the same password using the first 2 chars of the encrypted one
from the database as the salt. I really don't have any idea what is going on
anyone?
Regards,
Joseph