Re: How crypting passwords in DB
| From: | Scott Courtney | Date: | Wed, 27 Dec 2000 22:47:33 +0000 |
| Subject: | Re: How crypting passwords in DB | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-32017@lists.php.net to get a copy of this message | ||
Anuradha Ratnaweera <anuradha@gnu.org> wrote:
> On Wed, 27 Dec 2000 ouldm@linux-at-business.com wrote:
>
> > In reality I'm asking for the two cases. i.e. encrypting passwords in
> > my database and not allow password to be clear when user sign up in
> > the pop-up (user, password) on my site.
>
> When the user sends a password, calculate it's MD5 hash (a 32 byte string)
>
> $md5 = md5($HTTP_POST_VARS["password"]);
>
> and insert this value to the database instead of plain text. When the user
> logs in, test MD5 hash of the password he sends with the one in the
> database.
>
> Anuradha
Correct. It's also good practice to concatenate the userid and a linefeed
and the password before doing the md5() call, so that two users who happen
to pick the same password won't get the same crypt string.
In other words,
$string = $HTTP_POST_VARS["login"] . "\n" .
$HTTP_POST_VARS["password"];
$md5 = md5($string);
That generates the value that should either be stored into the database
(creating a new account or changing the password) or compared with the
value already in the database (validating a login).
I posted a more complete description of this, with code examples, on the
PHP DB list a few days ago. Check the archives if you're interested.
Scott Courtney