RE: [PHP] ok, I ask again.. how to encrypt to be able to match database info?
| From: | CompMan86 | Date: | Tue, 22 Jan 2002 22:26:59 +0000 |
| Subject: | RE: [PHP] ok, I ask again.. how to encrypt to be able to match database info? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-81604@lists.php.net to get a copy of this message | ||
The mysql function password() uses a one way encryption algorithm, as
does crypt(). Once you add a user with encrypted password, you can
compare the user's attempted login attempt using select
password('$password'). It will just echo back to you the encrypted
password. However, this requires you sending the unencrypted password to
the mysql server, which is a possible security risk if you're paranoid
(although you'd have to send the unencrypted password anyway when you
add the user). A workaround to this problem would be to use crypt().
That way, the encrypted password never leaves PHP, and it requires one
less MYSQL query. Since crypt is not reversible, I don't see why
password() would be preferred over crypt(). To clarify:
<?
//encrypt users attempted password
$pass = crypt($pass);
//connect to database and get the stored encrypted password
//I won't bother including that code
mysql_query("SELECT password($password)");
$row = mysql_fetch_assoc();
if ($row['password'] == $pass) {
echo "Password is good";
}
else
echo "Your password is incorrect";
?>
Hope this helps
-----Original Message-----
From: Tom Rogers [mailto:trogers@kwikin.com]
Sent: Monday, January 21, 2002 7:21 PM
To: Hawk; php-general@lists.php.net
Subject: Re: [PHP] ok, I ask again.. how to encrypt to be able to match
database info?
Hi
Encrypt the password from the form using the same salt value as the one
used for the database then compare them...
Tom
At 05:36 22/01/02, Hawk wrote:
>I've asked this several times but it doesn't seem like anyone
understands my
>problem, the passwords are encrypted in the database, but I don't know
how
>to match an unencrypted password from the login form with the database?
>is it possible to encrypt the password I sent from the form in php or
does
>that have to be done in mysql?
>in any case, how do I do it?
>If you don't have anything bright to say, don't, in some of the replys
I've
>had earlier it sounds like you think I'm an idiot...
>And even if I am, I don't want to be refered as one ;)
>
>
>
>
>--
>PHP General Mailing List (http://www.php.net/)
>To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
>For additional commands, e-mail: php-general-help@lists.php.net
>To contact the list administrators, e-mail:
php-list-admin@lists.php.net