note 25210 added to function.md5

From: Date: Sat, 14 Sep 2002 12:16:52 +0000
Subject: note 25210 added to function.md5
Groups: php.notes 
Request: Send a blank email to php-notes+get-36675@lists.php.net to get a copy of this message
Responding to willmoss@btinternet.com's post... This would be EXTREMELY dangerous to implement in this fashion. If I knew this to be your security scheme, all I would have to do is to create ANY user in your database to be able to hack into ANY user account. Here's how: I create a user "Ron" with a Password of "FOO" Then I log in to another account, say "Will", using password "FOO". Your code will match MY password and return 1 row. You MUST change your query to include the username, i.e.: $result = mysql_query("SELECT * FROM users WHERE encrypted_password='$user_submitted_password' AND USERNAME='$USER_SUBMITTED_USERNAME'"); I'm sure this is what you meant when you posted your example, but I thought I should point this out so that some folks won't take your code and implement it without thinking. -- http://www.php.net/manual/en/function.md5.php http://master.php.net/manage/user-notes.php?action=edit+25210 http://master.php.net/manage/user-notes.php?action=delete+25210 http://master.php.net/manage/user-notes.php?action=reject+25210

« previous php.notes (#36675) next »