RE: [PHP] ok, I ask again.. how to encrypt to be able to match database info?

From: Date: Tue, 22 Jan 2002 22:26:59 +0000
Subject: RE: [PHP] ok, I ask again.. how to encrypt to be able to match database info?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-81604@lists.php.net to get a copy of this message
The mysql function password() uses a one way encryption algorithm, as does crypt(). Once you add a user with encrypted password, you can compare the user's attempted login attempt using select password('$password'). It will just echo back to you the encrypted password. However, this requires you sending the unencrypted password to the mysql server, which is a possible security risk if you're paranoid (although you'd have to send the unencrypted password anyway when you add the user). A workaround to this problem would be to use crypt(). That way, the encrypted password never leaves PHP, and it requires one less MYSQL query. Since crypt is not reversible, I don't see why password() would be preferred over crypt(). To clarify: <? //encrypt users attempted password $pass = crypt($pass); //connect to database and get the stored encrypted password //I won't bother including that code mysql_query("SELECT password($password)"); $row = mysql_fetch_assoc(); if ($row['password'] == $pass) { echo "Password is good"; } else echo "Your password is incorrect"; ?> Hope this helps -----Original Message----- From: Tom Rogers [mailto:trogers@kwikin.com] Sent: Monday, January 21, 2002 7:21 PM To: Hawk; php-general@lists.php.net Subject: Re: [PHP] ok, I ask again.. how to encrypt to be able to match database info? Hi Encrypt the password from the form using the same salt value as the one used for the database then compare them... Tom At 05:36 22/01/02, Hawk wrote: >I've asked this several times but it doesn't seem like anyone understands my >problem, the passwords are encrypted in the database, but I don't know how >to match an unencrypted password from the login form with the database? >is it possible to encrypt the password I sent from the form in php or does >that have to be done in mysql? >in any case, how do I do it? >If you don't have anything bright to say, don't, in some of the replys I've >had earlier it sounds like you think I'm an idiot... >And even if I am, I don't want to be refered as one ;) > > > > >-- >PHP General Mailing List (http://www.php.net/) >To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net >For additional commands, e-mail: php-general-help@lists.php.net >To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#81604) next »