note 51041 added to security.database.storage
| From: | JimPlush-jiminoc at gmail dot com | Date: | Thu, 17 Mar 2005 21:45:43 +0000 |
| Subject: | note 51041 added to security.database.storage | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-86600@lists.php.net to get a copy of this message | ||
Another handy trick is to use MD5 with a "salt". Which basically means appending another
static string to your $password variable to help prevent against dictionary attacks.
Example:
config.php - KEEP THIS OUTSIDE THE WEBROOT
define("PHP_SALT", "iLov3pHp5");
----------------------------------------------
and when you add your database query you would do:
// storing password hash
$query = sprintf("INSERT INTO users(name,pwd) VALUES('%s','%s');",
addslashes($username), md5($password.PHP_SALT));
This way if a user's password is "DOG" it can't be guessed easily because their
password gets saved to the DB as the MD5 version of "DOGiLov3pHp5". Last time I checked,
that wasn't in the dictionary :)
----
Manual Page -- http://www.php.net/manual/en/security.database.storage.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+51041
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+51041&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+51041&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+51041&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+51041&report=yes&reason=useless
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+51041&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+51041&report=yes
Search -- http://master.php.net/manage/user-notes.php