Hi all,
I've been pulling my hair out trying to figure out what's wrong. I think my method is wrong.
The code works fine with plain text passwords but I can't seem to figure out how to use salt!
PHP Code:
<?php
$username = $_POST['username'];
$password = $_POST['password'];
if (selectFromDB() == md5(md5($password).$count['salt'])) {
echo "Accept";
} else {
echo "Denied";
}
function selectFromDB() {
global $username;
//Database service vars
$databasehost = "localhost";
$databasename = "nes";
$databasetable = "test";
$databaseusername ="root";
$databasepassword = "password";
$con = mysql_connect($databasehost,$databaseusername,$databasepassword) or die(mysql_error());
mysql_select_db($databasename) or die(mysql_error());
$query = "SELECT password,salt FROM user WHERE username='$username'";
$result = mysql_query($query);
$count = mysql_num_rows($result);
if ($count)
{
$output = mysql_result($result, 0);
return $output;
}
else
{
return "0";
}
mysql_free_result($result);
mysql_close($con);
}
?>
Thanks for your time