Re: AUTH security question

From: Date: Mon, 12 May 2003 19:22:54 +0000
Subject: Re: AUTH security question
References: 1  Groups: php.pear.general 
Request: Send a blank email to pear-general+get-5337@lists.php.net to get a copy of this message
On Mon May 12, 2003 at 02:0628PM -0500, Geoff Hankerson wrote: > It seems you have to use an MD5 encrypted passwod in your DB table which > is fine, and I want to use a static salt key like this: > > Users table: > UserID > UserName > Password > PassEncr > > > $conn->query("SELECT * FROM Users WHERE PassEncr='" . > md5($_POST("password") . "MyStaticSaltKey") . "'"; There is no easy way to do this with the current version of PEAR::Auth. If you want to provide a patch, just go ahead. I already have some other patches pending, which I have to take care of. > (Unfortunately the PEAR site is really flakey today and I can't seem to > access the docs on AUTH - so go easy on me if I am missing something > simple). We had some issues with mysqld on pear.php.net. At the time of writing this, everything seems to be ok again. > Also is there any drawback security wise to having the clear text > password and MD5 encrypted password in the same table? Storing passwords in plaintext in prominent places like databases is a security risk in every situation. > It seems almost necessary for a site with hundreds or thousands of users. There are a number of mechanisms to circumvent this. One might be to change the password, if the user has forgotten it, and email it to him. -- - Martin Martin Jansen http://martinjansen.com/

« previous php.pear.general (#5337) next »