note 25761 added to function.md5

From: Date: Fri, 04 Oct 2002 16:04:40 +0000
Subject: note 25761 added to function.md5
Groups: php.notes 
Request: Send a blank email to php-notes+get-37671@lists.php.net to get a copy of this message
[From a post above:] $user_submitted_password = md5($user_submitted_password); $result = mysql_query("SELECT * FROM users WHERE encrypted_password='$user_submitted_password'"); if (mysql_num_rows($result) < 1) { echo "Invalid password"; exit; } else { echo "Correct password!"; } [/From a post above] This would be quite stupid, especially with a large user-database: If -one of the passwords in the database- matches the entered one, the "Correct password!" will be echoed! I know this is a late reply, but just something that shocked my while reading through the comments ;) -- http://www.php.net/manual/en/function.md5.php http://master.php.net/manage/user-notes.php?action=edit+25761 http://master.php.net/manage/user-notes.php?action=delete+25761 http://master.php.net/manage/user-notes.php?action=reject+25761

« previous php.notes (#37671) next »