Re: How crypting passwords in DB

From: Date: Wed, 27 Dec 2000 22:47:33 +0000
Subject: Re: How crypting passwords in DB
Groups: php.general 
Request: Send a blank email to php-general+get-32017@lists.php.net to get a copy of this message
Anuradha Ratnaweera <anuradha@gnu.org> wrote: > On Wed, 27 Dec 2000 ouldm@linux-at-business.com wrote: > > > In reality I'm asking for the two cases. i.e. encrypting passwords in > > my database and not allow password to be clear when user sign up in > > the pop-up (user, password) on my site. > > When the user sends a password, calculate it's MD5 hash (a 32 byte string) > > $md5 = md5($HTTP_POST_VARS["password"]); > > and insert this value to the database instead of plain text. When the user > logs in, test MD5 hash of the password he sends with the one in the > database. > > Anuradha Correct. It's also good practice to concatenate the userid and a linefeed and the password before doing the md5() call, so that two users who happen to pick the same password won't get the same crypt string. In other words, $string = $HTTP_POST_VARS["login"] . "\n" . $HTTP_POST_VARS["password"]; $md5 = md5($string); That generates the value that should either be stored into the database (creating a new account or changing the password) or compared with the value already in the database (validating a login). I posted a more complete description of this, with code examples, on the PHP DB list a few days ago. Check the archives if you're interested. Scott Courtney

« previous php.general (#32017) next »