note 61564 deleted from function.mt-rand by mazzanet
| From: | mazzanet@php.net | Date: | Tue, 07 Feb 2006 10:02:47 +0000 |
| Subject: | note 61564 deleted from function.mt-rand by mazzanet | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-103170@lists.php.net to get a copy of this message | ||
Note Submitter: kbater at gmail dot com
----
personally, for password protection, i use the md5 encryption method. It's especially good, so
that if someone hacks into your database, they can't get view peoples passwords to thier
accounts.... other than the fact that they will see and be able to change everything without knowing
thier password, but if you're a host, it's a good idea to use the md5 encryption.
example:
<?php
mysql_connect('localhost', 'user', 'pass') or die('Cannot
connect to mySQL Database. '.mysql_error());
mysql_select_db('db') or die('Cannot select mySQL Database. '.mysql_error());
if ($_POST['submit']) { // if the submit button has been pressed...
$query = "SELECT * FROM
users WHERE user =
'$_POST[username]' LIMIT 1";
$result = mysql_query($query) or die('Cannot preform mySQL query on database.
'.$mysql_error());
$rows = mysql_num_rows($result); //check to see if username is in database
$fetch = mysql_fetch_array($result); // Get the info out of the database
if ($rows = 0) { // if there is no username:
die('No such username or password is incorrect.');
}
else if (!$_POST['password'] = md5($fetch['password'])) { // if the password
is not the same as the md5 encryption of the password:
die('No such username or password is incorrect.');
}
else {
echo 'Successfully logged in! <a
href="nextpage.php">Continue!</a>';
}
}
else {
login();
}
?>
now, all you need to add to your other script that puts the info into the database for you is:
<?
// rest of your code before the insert
$password = md5($_POST['password']);
$query = "INSERT INTO blah blah blah..."
// rest of your code
?>
IT'S SO MUCH SAFER TO USE ON ANY SITE!!!!!!!!!!!
p.s. since the rest of the post's were about creating random passwords, just use this on like,
3 random letters, and you'll get like 8 or something, depending on the letters, so it's
totally un-encryptable unless they know it's a md5 encrytpion
any questions, e-mail me!