Re: password encryption ...
| From: | Dell Coleman | Date: | Tue, 18 Jul 2000 18:58:56 +0000 |
| Subject: | Re: password encryption ... | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-7125@lists.php.net to get a copy of this message | ||
Hi
It may be easier to use the mysql password() function when storing the
password. You also use it again when doing the query to see if the
user/password combo are valid (assuming mysql is your db)
Something like
mysql_query("insert into mytable(user,password) values
('$user',password('$password'))"),$db;
would do the storing
A query like
$sql = "SELECT *
FROM mytable
WHERE user='$PHP_AUTH_USER' and
password=password('$PHP_AUTH_PW')";
should get it back
HTH
Dell Coleman
David VanHorn wrote:
>
> >
> >I'm using the same functions to do all this ..
> >as when I was using the form entry ..
> >All I'm doing is changing where the username and password come from ..
>
> That may be the key.
> I have it working here, but I'm taking my input from a plain old form.
> md5($Pass) results in "stuff" which is identical to what I stored when the
> user set up his account, which took his password string, ran md5($Pass) and
> stored the result in the database.
>
> --
> www.SpamWhack.com A pre-emptive strike against spam
> Where's dave? Ö›
> õ¢[æ° !zivàVhttp://www.findu.com/cgi-bin/find.cgi?kc6ete-9
>
> My transistor sings
> with unintended parasitic
> the smoke escapes
>
> By Jeff Stout
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net