note 29688 deleted from function.crypt by aidan
| From: | aidan@php.net | Date: | Mon, 05 Jul 2004 10:28:03 +0000 |
| Subject: | note 29688 deleted from function.crypt by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-72585@lists.php.net to get a copy of this message | ||
Note Submitter: Stalizard
----
took me a bit of time but I found a way to check passwords entered from a web form to check against
the md5 hash in /etc/shadow
I had setup IC radius and imported all users from /etc/shadow. I needed a way to check users
passwords thru the web so that they could check usage. i could have used the testrad bash script
but that was just not my way of doing things becase then every time a user tried to login to webpage
it would show up in radius log.
so saying all that, I now have all users in DB with a MD5 hash password stored.
so what I do it this
#Query the DB for the user that tried to login
$pass_query="SELECT * from TABLE where FieldUser='$usernamefromweb' and
attributefield='Password';";
$pass_results=mysql_query($pass_query);
$row=mysql_fetch_assoc($pass_results);
#$row[Value]=the MD5 hash
#user substr() to find out the salt
$salt = substr("$row[Value]", 0, 12);
# get salt from encrypted pass to check against
$passwordc = crypt("$password",$salt);
#now I have user inputed password encrypted using same salt as the one for his real pass
#now check passwords if the match
if ($passwordc == $row[Value]) {
echo "Password verified!";
}else{
echo ""Verify Failed;
exit();
}
Just adding a little knowledge to the list so that the next person wondering how to do this doesnt
go crazy like I did trying to fiqure out how to do it.