note 25761 deleted from function.md5 by jimw

From: Date: Sat, 08 Feb 2003 19:50:09 +0000
Subject: note 25761 deleted from function.md5 by jimw
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-43646@lists.php.net to get a copy of this message
[From a post above:] $user_submitted_password = md5($user_submitted_password); $result = mysql_query("SELECT * FROM users WHERE encrypted_password='$user_submitted_password'"); if (mysql_num_rows($result) < 1) { echo "Invalid password"; exit; } else { echo "Correct password!"; } [/From a post above] This would be quite stupid, especially with a large user-database: If -one of the passwords in the database- matches the entered one, the "Correct password!" will be echoed! I know this is a late reply, but just something that shocked my while reading through the comments ;)

« previous php.notes (#43646) next »