note 29688 deleted from function.crypt by aidan

From: Date: Mon, 05 Jul 2004 10:28:03 +0000
Subject: note 29688 deleted from function.crypt by aidan
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-72585@lists.php.net to get a copy of this message
Note Submitter: Stalizard ---- took me a bit of time but I found a way to check passwords entered from a web form to check against the md5 hash in /etc/shadow I had setup IC radius and imported all users from /etc/shadow. I needed a way to check users passwords thru the web so that they could check usage. i could have used the testrad bash script but that was just not my way of doing things becase then every time a user tried to login to webpage it would show up in radius log. so saying all that, I now have all users in DB with a MD5 hash password stored. so what I do it this #Query the DB for the user that tried to login $pass_query="SELECT * from TABLE where FieldUser='$usernamefromweb' and attributefield='Password';"; $pass_results=mysql_query($pass_query); $row=mysql_fetch_assoc($pass_results); #$row[Value]=the MD5 hash #user substr() to find out the salt $salt = substr("$row[Value]", 0, 12); # get salt from encrypted pass to check against $passwordc = crypt("$password",$salt); #now I have user inputed password encrypted using same salt as the one for his real pass #now check passwords if the match if ($passwordc == $row[Value]) { echo "Password verified!"; }else{ echo ""Verify Failed; exit(); } Just adding a little knowledge to the list so that the next person wondering how to do this doesnt go crazy like I did trying to fiqure out how to do it.

« previous php.notes (#72585) next »