Go Back   CodingForums.com > :: Server side development > PHP

Before you post, read our: Rules & Posting Guidelines

Reply
 
Thread Tools Rate Thread
Enjoy an ad free experience by logging in. Not a member yet? Register.
Old 08-20-2007, 09:48 PM   PM User | #1
moos3
Regular Coder

 
Join Date: Aug 2007
Location: maine,usa
Posts: 151
Thanks: 2
Thanked 1 Time in 1 Post
moos3 is an unknown quantity at this point
User passwords for login

I'm trying to figure out the best way to store them. in my database? sha or md5 or something else.
moos3 is offline   Reply With Quote
Old 08-20-2007, 10:06 PM   PM User | #2
PappaJohn
Senior Coder

 
Join Date: Apr 2007
Location: Quakertown PA USA
Posts: 1,028
Thanks: 1
Thanked 125 Times in 123 Posts
PappaJohn will become famous soon enough
I typically hash them using sha1(), it is somewhat more secure than md5.
PappaJohn is offline   Reply With Quote
Old 08-20-2007, 11:29 PM   PM User | #3
wordnerd
New Coder

 
Join Date: Dec 2006
Location: Denver, Colorado
Posts: 17
Thanks: 0
Thanked 0 Times in 0 Posts
wordnerd is an unknown quantity at this point
For what it's worth, I also always store passwords as sha1() hashes. VARCHAR(40) holds them nicely.
wordnerd is offline   Reply With Quote
Old 08-21-2007, 06:20 AM   PM User | #4
fl00d
Regular Coder

 
Join Date: Mar 2007
Location: Quebec
Posts: 261
Thanks: 6
Thanked 7 Times in 7 Posts
fl00d has a little shameless behaviour in the past
hmm I use MD5(). I've just thought up an idea to double MD5 encryption. Have the password hashed once, and then the hashed value hashed again. I'm about to test it out and see how easy it would be to crack an hash that also has a hash value. My instinct tells me it would be fairly easy to crack but I'll find out for sure
fl00d is offline   Reply With Quote
Old 08-21-2007, 02:51 PM   PM User | #5
westmatrix99
Regular Coder

 
westmatrix99's Avatar
 
Join Date: Dec 2006
Location: South Africa
Posts: 307
Thanks: 12
Thanked 0 Times in 0 Posts
westmatrix99 is an unknown quantity at this point
Sorry for this odd question but does your site actually get cracked? (not hacked but cracked)
What would they gain?
I mean your'e not a bank or anything are you?
__________________
Thanks for you support!
westmatrix99 is offline   Reply With Quote
Old 08-21-2007, 03:00 PM   PM User | #6
Inigoesdr
Super Moderator


 
Inigoesdr's Avatar
 
Join Date: Mar 2007
Location: Florida, USA
Posts: 3,601
Thanks: 2
Thanked 397 Times in 390 Posts
Inigoesdr is a jewel in the roughInigoesdr is a jewel in the roughInigoesdr is a jewel in the rough
Quote:
Originally Posted by fl00d View Post
hmm I use MD5(). I've just thought up an idea to double MD5 encryption. Have the password hashed once, and then the hashed value hashed again.
vBulletin uses something similar to that, with a random salt added.

Quote:
Originally Posted by westmatrix99 View Post
Sorry for this odd question but does your site actually get cracked? (not hacked but cracked)
What would they gain?
I mean your'e not a bank or anything are you?
It doesn't matter.. no one wants their site cracked. Whether you run a bank or a blog, it's always a bad thing.
Inigoesdr is offline   Reply With Quote
Users who have thanked Inigoesdr for this post:
westmatrix99 (08-21-2007)
Old 08-21-2007, 03:03 PM   PM User | #7
westmatrix99
Regular Coder

 
westmatrix99's Avatar
 
Join Date: Dec 2006
Location: South Africa
Posts: 307
Thanks: 12
Thanked 0 Times in 0 Posts
westmatrix99 is an unknown quantity at this point
Ok it's personal preference.
__________________
Thanks for you support!
westmatrix99 is offline   Reply With Quote
Old 08-21-2007, 03:08 PM   PM User | #8
Inigoesdr
Super Moderator


 
Inigoesdr's Avatar
 
Join Date: Mar 2007
Location: Florida, USA
Posts: 3,601
Thanks: 2
Thanked 397 Times in 390 Posts
Inigoesdr is a jewel in the roughInigoesdr is a jewel in the roughInigoesdr is a jewel in the rough
It shouldn't be personal preference. You have an implied responsibility to do the most you can to protect your users' personal information.
Inigoesdr is offline   Reply With Quote
Old 08-21-2007, 03:14 PM   PM User | #9
westmatrix99
Regular Coder

 
westmatrix99's Avatar
 
Join Date: Dec 2006
Location: South Africa
Posts: 307
Thanks: 12
Thanked 0 Times in 0 Posts
westmatrix99 is an unknown quantity at this point
All I am saying is that unless you are a bank or store some serious information then hashing and bashing makes no sense.

Ok what you say is true that you should protect the data but trying to crack a website is childish.

It's never happened to me. ("touch wood")
I would love to see someone try and crack my site and hear how long it took them to figure out that they can't.
__________________
Thanks for you support!
westmatrix99 is offline   Reply With Quote
Old 08-21-2007, 03:16 PM   PM User | #10
Inigoesdr
Super Moderator


 
Inigoesdr's Avatar
 
Join Date: Mar 2007
Location: Florida, USA
Posts: 3,601
Thanks: 2
Thanked 397 Times in 390 Posts
Inigoesdr is a jewel in the roughInigoesdr is a jewel in the roughInigoesdr is a jewel in the rough
Quote:
Originally Posted by westmatrix99 View Post
All I am saying is that unless you are a bank or store some serious information then hashing and bashing makes no sense.

Ok what you say is true that you should protect the data but trying to crack a website is childish.

It's never happened to me. ("touch wood")
I would love to see someone try and crack my site and hear how long it took them to figure out that they can't.
No offense, but just because it's childish doesn't mean people won't do it.
And I seriously doubt that your site can't be cracked. If it's connected to the internet, then there's a way to get to it.
Inigoesdr is offline   Reply With Quote
Old 08-21-2007, 03:21 PM   PM User | #11
westmatrix99
Regular Coder

 
westmatrix99's Avatar
 
Join Date: Dec 2006
Location: South Africa
Posts: 307
Thanks: 12
Thanked 0 Times in 0 Posts
westmatrix99 is an unknown quantity at this point
Cool cheers.
__________________
Thanks for you support!
westmatrix99 is offline   Reply With Quote
Old 08-21-2007, 03:28 PM   PM User | #12
rafiki
Senior Coder

 
rafiki's Avatar
 
Join Date: Aug 2006
Location: Floating around somewhere...
Posts: 2,034
Thanks: 18
Thanked 42 Times in 42 Posts
rafiki will become famous soon enough
i sha1() passwords all the time probably always will.
__________________
Get Firefox Now
rafiki is offline   Reply With Quote
Users who have thanked rafiki for this post:
westmatrix99 (08-21-2007)
Old 08-21-2007, 03:34 PM   PM User | #13
Inigoesdr
Super Moderator


 
Inigoesdr's Avatar
 
Join Date: Mar 2007
Location: Florida, USA
Posts: 3,601
Thanks: 2
Thanked 397 Times in 390 Posts
Inigoesdr is a jewel in the roughInigoesdr is a jewel in the roughInigoesdr is a jewel in the rough
I call your sha1() and raise you hash('sha256', $string);
Inigoesdr is offline   Reply With Quote
Users who have thanked Inigoesdr for this post:
rafiki (08-21-2007)
Old 08-21-2007, 03:38 PM   PM User | #14
rafiki
Senior Coder

 
rafiki's Avatar
 
Join Date: Aug 2006
Location: Floating around somewhere...
Posts: 2,034
Thanks: 18
Thanked 42 Times in 42 Posts
rafiki will become famous soon enough
fold. lol
__________________
Get Firefox Now
rafiki is offline   Reply With Quote
Users who have thanked rafiki for this post:
westmatrix99 (08-21-2007)
Old 08-21-2007, 07:04 PM   PM User | #15
moos3
Regular Coder

 
Join Date: Aug 2007
Location: maine,usa
Posts: 151
Thanks: 2
Thanked 1 Time in 1 Post
moos3 is an unknown quantity at this point
I'm going to do the following
PHP Code:
$temp sha1($passwd);
$password md5($temp);
$salt substr(md5(uniqid(rand(), true)), 05);
$secure_password md5($salt md5($password)); 
Suggestions?
moos3 is offline   Reply With Quote
Reply

Bookmarks

Jump To Top of Thread


Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 07:09 PM.


Advertisement
Log in to turn off these ads.