note 25761 added to function.md5
| From: | The_DJB at hotmail dot com | Date: | Fri, 04 Oct 2002 16:04:40 +0000 |
| Subject: | note 25761 added to function.md5 | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-37671@lists.php.net to get a copy of this message | ||
[From a post above:]
$user_submitted_password = md5($user_submitted_password);
$result = mysql_query("SELECT * FROM users WHERE
encrypted_password='$user_submitted_password'");
if (mysql_num_rows($result) < 1) { echo "Invalid password"; exit; }
else { echo "Correct password!"; }
[/From a post above]
This would be quite stupid, especially with a large user-database: If -one of the passwords in the
database- matches the entered one, the "Correct password!" will be echoed!
I know this is a late reply, but just something that shocked my while reading through the comments
;)
--
http://www.php.net/manual/en/function.md5.php
http://master.php.net/manage/user-notes.php?action=edit+25761
http://master.php.net/manage/user-notes.php?action=delete+25761
http://master.php.net/manage/user-notes.php?action=reject+25761