AUTH security question
| From: | Geoff Hankerson | Date: | Mon, 12 May 2003 19:06:28 +0000 |
| Subject: | AUTH security question | ||
| Groups: | php.pear.general | ||
| Request: | Send a blank email to pear-general+get-5336@lists.php.net to get a copy of this message | ||
I'm looking at the AUTH package for the first time and got a basic example working without much trouble.
It seems you have to use an MD5 encrypted passwod in your DB table which is fine, and I want to use a static salt key like this:
Users table:
UserID
UserName
Password
PassEncr
$conn->query("SELECT * FROM Users WHERE PassEncr='" . md5($_POST("password") . "MyStaticSaltKey") . "'";
How do I do this? I don't see how I can accomplish this with AUTH. (Unfortunately the PEAR site is really flakey today and I can't seem to access the docs on AUTH - so go easy on me if I am missing something simple).
Also is there any drawback security wise to having the clear text password and MD5 encrypted password in the same table?
It seems almost necessary for a site with hundreds or thousands of users.