note 25210 rejected from function.md5 by nicos
| From: | nicos@php.net | Date: | Sat, 14 Sep 2002 14:11:00 +0000 |
| Subject: | note 25210 rejected from function.md5 by nicos | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-36677@lists.php.net to get a copy of this message | ||
Responding to willmoss@btinternet.com's post...
This would be EXTREMELY dangerous to implement in this fashion.
If I knew this to be your security scheme, all I would have to do is to create ANY user in your
database to be able to hack into ANY user account.
Here's how:
I create a user "Ron" with a Password of "FOO"
Then I log in to another account, say "Will", using password "FOO".
Your code will match MY password and return 1 row.
You MUST change your query to include the username, i.e.:
$result = mysql_query("SELECT * FROM users WHERE
encrypted_password='$user_submitted_password'
AND USERNAME='$USER_SUBMITTED_USERNAME'");
I'm sure this is what you meant when you posted your example, but I thought I should point this
out so that some folks won't take your code and implement it without thinking.