AUTH security question

From: Date: Mon, 12 May 2003 19:06:28 +0000
Subject: AUTH security question
Groups: php.pear.general 
Request: Send a blank email to pear-general+get-5336@lists.php.net to get a copy of this message
I'm looking at the AUTH package for the first time and got a basic example working without much trouble. It seems you have to use an MD5 encrypted passwod in your DB table which is fine, and I want to use a static salt key like this: Users table: UserID UserName Password PassEncr $conn->query("SELECT * FROM Users WHERE PassEncr='" . md5($_POST("password") . "MyStaticSaltKey") . "'"; How do I do this? I don't see how I can accomplish this with AUTH. (Unfortunately the PEAR site is really flakey today and I can't seem to access the docs on AUTH - so go easy on me if I am missing something simple). Also is there any drawback security wise to having the clear text password and MD5 encrypted password in the same table? It seems almost necessary for a site with hundreds or thousands of users.

« previous php.pear.general (#5336) next »