note 40225 deleted from function.md5 by danbrown

From: Date: Mon, 20 Jun 2011 15:22:10 +0000
Subject: note 40225 deleted from function.md5 by danbrown
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-180749@lists.php.net to get a copy of this message
Note Submitter: brian_bisaillon at rogers dot com ---- Source code to create SSHA passwords... public function HashPassword($password) { mt_srand((double)microtime()*1000000); $salt = mhash_keygen_s2k(MHASH_SHA1, $password, substr(pack('h*', md5(mt_rand())), 0, 8), 4); $hash = "{SSHA}".base64_encode(mhash(MHASH_SHA1, $password.$salt).$salt); return $hash; } Source code to validate SSHA passwords... public function ValidatePassword($password, $hash) { $hash = base64_decode(substr($hash, 6)); $original_hash = substr($hash, 0, 20); $salt = substr($hash, 20); $new_hash = mhash(MHASH_SHA1, $password . $salt); if (strcmp($original_hash, $new_hash) == 0) ... do something because your password is valid ... else echo 'Unauthorized: Authorization has been refused for the credentials you provided. Please login with a valid username and password.'; ... be sure to clear your session data ... } Note: The format is compatible with OpenLDAP's SSHA scheme if I'm not mistaken.

« previous php.notes (#180749) next »