note 51041 added to security.database.storage

From: Date: Thu, 17 Mar 2005 21:45:43 +0000
Subject: note 51041 added to security.database.storage
Groups: php.notes 
Request: Send a blank email to php-notes+get-86600@lists.php.net to get a copy of this message
Another handy trick is to use MD5 with a "salt". Which basically means appending another static string to your $password variable to help prevent against dictionary attacks. Example: config.php - KEEP THIS OUTSIDE THE WEBROOT define("PHP_SALT", "iLov3pHp5"); ---------------------------------------------- and when you add your database query you would do: // storing password hash $query = sprintf("INSERT INTO users(name,pwd) VALUES('%s','%s');", addslashes($username), md5($password.PHP_SALT)); This way if a user's password is "DOG" it can't be guessed easily because their password gets saved to the DB as the MD5 version of "DOGiLov3pHp5". Last time I checked, that wasn't in the dictionary :) ---- Manual Page -- http://www.php.net/manual/en/security.database.storage.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+51041 Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+51041&report=yes&reason=added+to+the+manual Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+51041&report=yes&reason=bad+code Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+51041&report=yes&reason=spam Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+51041&report=yes&reason=useless Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+51041&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+51041&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#86600) next »