note 29688 added to function.crypt
| From: | Stalizard at rack1 dot php dot net | Date: | Fri, 21 Feb 2003 17:07:11 +0000 |
| Subject: | note 29688 added to function.crypt | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-44317@lists.php.net to get a copy of this message | ||
took me a bit of time but I found a way to check passwords entered from a web form to check against
the md5 hash in /etc/shadow
I had setup IC radius and imported all users from /etc/shadow. I needed a way to check users
passwords thru the web so that they could check usage. i could have used the testrad bash script
but that was just not my way of doing things becase then every time a user tried to login to webpage
it would show up in radius log.
so saying all that, I now have all users in DB with a MD5 hash password stored.
so what I do it this
#Query the DB for the user that tried to login
$pass_query="SELECT * from TABLE where FieldUser='$usernamefromweb' and
attributefield='Password';";
$pass_results=mysql_query($pass_query);
$row=mysql_fetch_assoc($pass_results);
#$row[Value]=the MD5 hash
#user substr() to find out the salt
$salt = substr("$row[Value]", 0, 12);
# get salt from encrypted pass to check against
$passwordc = crypt("$password",$salt);
#now I have user inputed password encrypted using same salt as the one for his real pass
#now check passwords if the match
if ($passwordc == $row[Value]) {
echo "Password verified!";
}else{
echo ""Verify Failed;
exit();
}
Just adding a little knowledge to the list so that the next person wondering how to do this doesnt
go crazy like I did trying to fiqure out how to do it.
--
http://www.php.net/manual/en/function.crypt.php
http://master.php.net/manage/user-notes.php?action=edit+29688
http://master.php.net/manage/user-notes.php?action=delete+29688
http://master.php.net/manage/user-notes.php?action=reject+29688