Re: Shadow Passwords
| From: | Jim Winstead | Date: | Sun, 16 Dec 2001 20:08:30 +0000 |
| Subject: | Re: Shadow Passwords | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-3498@lists.php.net to get a copy of this message | ||
Paul Meagher <paul@datavore.com> wrote:
> To invoke MD5 from the crypt function you need to give it a 12 character
> salt instead of a 2 character salt.
>
> Just change this:
>
> crypt($pass,substr($this->users[$user],0,2))
>
> To this:
>
> crypt($pass,substr($this->users[$user],0,12))
to the best of my knowledge, you can always just pass the full crypted
password in as the salt. the underlying crypt() implementation will just
use the relevant bits by itself.
jim