Re: encryption
| From: | Andrey Hristov | Date: | Thu, 06 Dec 2001 12:50:09 +0000 |
| Subject: | Re: encryption | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-76876@lists.php.net to get a copy of this message | ||
UPDATE members set passwd=PASSWORD(passwd);
"select login from members where PASSWORD($form_pass)=passwd;"
Regards,
Adnrey Hristov
----- Original Message -----
From: "Justin French" <justin@indent.com.au>
To: "php" <php-general@lists.php.net>
Sent: Thursday, December 06, 2001 2:32 PM
Subject: [PHP] encryption
> Hi,
>
> Can someone give me a brief over view of how to encrypt a password and
> store it in a MySQL DB, then be able to validate thier plain text
> password on login against the encrypted one on the DB?
>
>
> I'm guessing I:
>
> 1. encrypt the desired password with some sort of key (eg "blahblah")
> which is hidden in a protected directory
>
> 2. write the encrypted password to the database
>
>
> Next time the user logs in:
>
> 1. take thier plain-text password they submit to login
>
> 2. encrypt it with the same key
>
> 3. compare it to the one on the database
>
>
> Or, is there something i'm missing, some sort of gaping big arse
> security hole, or some set of functions which take care of a heap of
> this stuff for me?
>
> If someone could point me to the right encryption tools / links /
> tutorials, i'd be gratefull.
>
>
>
> TIA
>
> Justin French
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>
>