note 29688 added to function.crypt

From: Date: Fri, 21 Feb 2003 17:07:11 +0000
Subject: note 29688 added to function.crypt
Groups: php.notes 
Request: Send a blank email to php-notes+get-44317@lists.php.net to get a copy of this message
took me a bit of time but I found a way to check passwords entered from a web form to check against the md5 hash in /etc/shadow I had setup IC radius and imported all users from /etc/shadow. I needed a way to check users passwords thru the web so that they could check usage. i could have used the testrad bash script but that was just not my way of doing things becase then every time a user tried to login to webpage it would show up in radius log. so saying all that, I now have all users in DB with a MD5 hash password stored. so what I do it this #Query the DB for the user that tried to login $pass_query="SELECT * from TABLE where FieldUser='$usernamefromweb' and attributefield='Password';"; $pass_results=mysql_query($pass_query); $row=mysql_fetch_assoc($pass_results); #$row[Value]=the MD5 hash #user substr() to find out the salt $salt = substr("$row[Value]", 0, 12); # get salt from encrypted pass to check against $passwordc = crypt("$password",$salt); #now I have user inputed password encrypted using same salt as the one for his real pass #now check passwords if the match if ($passwordc == $row[Value]) { echo "Password verified!"; }else{ echo ""Verify Failed; exit(); } Just adding a little knowledge to the list so that the next person wondering how to do this doesnt go crazy like I did trying to fiqure out how to do it. -- http://www.php.net/manual/en/function.crypt.php http://master.php.net/manage/user-notes.php?action=edit+29688 http://master.php.net/manage/user-notes.php?action=delete+29688 http://master.php.net/manage/user-notes.php?action=reject+29688

« previous php.notes (#44317) next »