Re: /etc/shadow

From: Date: Thu, 05 Apr 2001 17:44:37 +0000
Subject: Re: /etc/shadow
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-47294@lists.php.net to get a copy of this message
Yeah, crypt() Don't forget the salt. I did the same thing. Moved all my users into a database table with unix encrypted passwords, and run a function that dumps them all out to my /etc/passwd file. It appends the database data onto a passwd.base file that I made, that includes all the protected system accounts. Of course, I only run this from a secure server, only one user with a very long and obscure userid and password can access that database in any way, no one else can telnet in, and the database can not be accessed of the net, and I used every other form of page authorization I could manage to put in, prior to getting to the page that does all this. Including Alias/ScriptAlias directives to move the files out of the DocumentRoot. And again, don't forget to generate a random salt argument. On 4/5/01 10:36 AM, "Diogo Saad" <diogo@ibnetwork.com.br> wrote: > Is there a function that encrypts a string the same way the shadow file > does??? > What I wanna make is a page that changes my unix account password .... > > Thanx > > > _______________________________ > Diogo Saad > diogo@ibnetwork.com.br > Inter Business Tecnologia e Serviços. > >

« previous php.general (#47294) next »