note 25210 added to function.md5
| From: | RonPHP at oes dot NO_SPAM_FOR_YOU dot org | Date: | Sat, 14 Sep 2002 12:16:52 +0000 |
| Subject: | note 25210 added to function.md5 | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-36675@lists.php.net to get a copy of this message | ||
Responding to willmoss@btinternet.com's post...
This would be EXTREMELY dangerous to implement in this fashion.
If I knew this to be your security scheme, all I would have to do is to create ANY user in your
database to be able to hack into ANY user account.
Here's how:
I create a user "Ron" with a Password of "FOO"
Then I log in to another account, say "Will", using password "FOO".
Your code will match MY password and return 1 row.
You MUST change your query to include the username, i.e.:
$result = mysql_query("SELECT * FROM users WHERE
encrypted_password='$user_submitted_password'
AND USERNAME='$USER_SUBMITTED_USERNAME'");
I'm sure this is what you meant when you posted your example, but I thought I should point this
out so that some folks won't take your code and implement it without thinking.
--
http://www.php.net/manual/en/function.md5.php
http://master.php.net/manage/user-notes.php?action=edit+25210
http://master.php.net/manage/user-notes.php?action=delete+25210
http://master.php.net/manage/user-notes.php?action=reject+25210