note 25761 deleted from function.md5 by jimw
| From: | jimw@php.net | Date: | Sat, 08 Feb 2003 19:50:09 +0000 |
| Subject: | note 25761 deleted from function.md5 by jimw | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-43646@lists.php.net to get a copy of this message | ||
[From a post above:]
$user_submitted_password = md5($user_submitted_password);
$result = mysql_query("SELECT * FROM users WHERE
encrypted_password='$user_submitted_password'");
if (mysql_num_rows($result) < 1) { echo "Invalid password"; exit; }
else { echo "Correct password!"; }
[/From a post above]
This would be quite stupid, especially with a large user-database: If -one of the passwords in the
database- matches the entered one, the "Correct password!" will be echoed!
I know this is a late reply, but just something that shocked my while reading through the comments
;)