Welcome! Log In Create A New Profile

Advanced

Re[2]: [PARTIAL SOLVED] Re: Auth user with postgresql

Max
February 21, 2012 02:12PM
21 февраля 2012, 20:45 от Giuseppe Tofoni <gt0057@gmail.com>:
>
> In PHP I used crypt($pass, CRYPT_STD_DES) and I tried with the
> following statement

CRYPT_STD_DES is just a constant that indicates whether standard
DES crypt() is availlable, so you should not use it as the salt - or if
you do, the salt will be "1" (or "0" if standard DES crypt() is not
available). You may want to use something like this instead:

if (CRYPT_STD_DES == 1) {
$salt = substr($username, 0, 2);
$encrypted_password = crypt($password, $salt);
}

You should regenerate your .htpasswd file using this approach
because the Apache htpasswd uses a random salt instead of
the first two characters of the username,

>
> postgres_query "SELECT user FROM usertable WHERE user=$user AND
> pwd=crypt($pass, substr(pwd, 1, 2))";

You should never use any part of whatever you're encrypting as the salt
because it greatly reduces encryption strength / entropy. By using the
first two characters of the password as the salt, you're revealing them
because the salt is stored in the first two characters of the resulting
crypt() hash:

crypt("test", "te") generates "teH0wLIpW0gyQ"
crypt("test", "XX") generates "XXF2OrGyU2fzk"

So you may want to use something like this:

postgres_query "SELECT user FROM usertable WHERE user=$user AND
pwd=crypt($pass, substr($user, 1, 2))";

Max
_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

Auth user with postgresql

Giuseppe Tofoni February 17, 2012 07:40AM

Re: Auth user with postgresql

Piotr Sikora February 17, 2012 07:50AM

Re: Auth user with postgresql

Francis Daly February 17, 2012 07:56AM

Re: Auth user with postgresql

Giuseppe Tofoni February 17, 2012 02:14PM

Re: Auth user with postgresql

Piotr Sikora February 17, 2012 02:28PM

Re: Auth user with postgresql

Giuseppe Tofoni February 17, 2012 03:26PM

Re: Auth user with postgresql

Piotr Sikora February 17, 2012 04:06PM

Re: Auth user with postgresql

Giuseppe Tofoni February 17, 2012 06:30PM

Re: Auth user with postgresql

Piotr Sikora February 17, 2012 07:08PM

Re: Auth user with postgresql

Giuseppe Tofoni February 18, 2012 05:50AM

Re: Auth user with postgresql

Piotr Sikora February 18, 2012 09:20AM

Re: Auth user with postgresql

Giuseppe Tofoni February 18, 2012 01:46PM

Re: Auth user with postgresql

Piotr Sikora February 18, 2012 02:12PM

[PARTIAL SOLVED] Re: Auth user with postgresql

Giuseppe Tofoni February 20, 2012 06:40PM

Re: [PARTIAL SOLVED] Re: Auth user with postgresql

ktm2 February 21, 2012 11:04AM

Re: [PARTIAL SOLVED] Re: Auth user with postgresql

Giuseppe Tofoni February 21, 2012 11:46AM

Re: [PARTIAL SOLVED] Re: Auth user with postgresql

ktm2 February 21, 2012 12:04PM

Re[2]: [PARTIAL SOLVED] Re: Auth user with postgresql

Max February 21, 2012 02:12PM

Re: [PARTIAL SOLVED] Re: Auth user with postgresql

Piotr Sikora February 21, 2012 02:20PM

Re: [PARTIAL SOLVED] Re: Auth user with postgresql

Giuseppe Tofoni February 21, 2012 02:24PM

Re[2]: [PARTIAL SOLVED] Re: Auth user with postgresql

Max February 21, 2012 09:04PM

Re: Re[2]: [PARTIAL SOLVED] Re: Auth user with postgresql

Edho Arief February 21, 2012 10:56PM

[SOLVED] Re: Auth user with postgresql

Giuseppe Tofoni February 22, 2012 05:34PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 137
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready