Re: AUTH security question
| From: | Martin Jansen | Date: | Mon, 12 May 2003 19:22:54 +0000 |
| Subject: | Re: AUTH security question | ||
| References: | 1 | Groups: | php.pear.general |
| Request: | Send a blank email to pear-general+get-5337@lists.php.net to get a copy of this message | ||
On Mon May 12, 2003 at 02:0628PM -0500, Geoff Hankerson wrote:
> It seems you have to use an MD5 encrypted passwod in your DB table which
> is fine, and I want to use a static salt key like this:
>
> Users table:
> UserID
> UserName
> Password
> PassEncr
>
>
> $conn->query("SELECT * FROM Users WHERE PassEncr='" .
> md5($_POST("password") . "MyStaticSaltKey") . "'";
There is no easy way to do this with the current version of
PEAR::Auth. If you want to provide a patch, just go ahead. I already
have some other patches pending, which I have to take care of.
> (Unfortunately the PEAR site is really flakey today and I can't seem to
> access the docs on AUTH - so go easy on me if I am missing something
> simple).
We had some issues with mysqld on pear.php.net. At the time of writing
this, everything seems to be ok again.
> Also is there any drawback security wise to having the clear text
> password and MD5 encrypted password in the same table?
Storing passwords in plaintext in prominent places like databases is a
security risk in every situation.
> It seems almost necessary for a site with hundreds or thousands of users.
There are a number of mechanisms to circumvent this. One might be to
change the password, if the user has forgotten it, and email it to
him.
--
- Martin Martin Jansen
http://martinjansen.com/