note 25210 rejected from function.md5 by nicos

From: Date: Sat, 14 Sep 2002 14:11:00 +0000
Subject: note 25210 rejected from function.md5 by nicos
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-36677@lists.php.net to get a copy of this message
Responding to willmoss@btinternet.com's post... This would be EXTREMELY dangerous to implement in this fashion. If I knew this to be your security scheme, all I would have to do is to create ANY user in your database to be able to hack into ANY user account. Here's how: I create a user "Ron" with a Password of "FOO" Then I log in to another account, say "Will", using password "FOO". Your code will match MY password and return 1 row. You MUST change your query to include the username, i.e.: $result = mysql_query("SELECT * FROM users WHERE encrypted_password='$user_submitted_password' AND USERNAME='$USER_SUBMITTED_USERNAME'"); I'm sure this is what you meant when you posted your example, but I thought I should point this out so that some folks won't take your code and implement it without thinking.

« previous php.notes (#36677) next »