Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
Register FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 08-09-2004, 10:38 PM
DrScion DrScion is offline
 
Join Date: Mar 2004
Posts: 6
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Password integration

This is for verification of member status only and is not being used to integrate with VB, but simply to allow login to another part of the site based on their username and password.

Ive searched on google.com and here and learned that the password pattern is:

PHP Code:
md5(md5('plain txt pwd' . salt)) 
Ive attempted to use this in numerous fasions, yet still wont match up with the password in the database, this coding is as follows,

PHP Code:
mysql_select_db($database_connect, $connect);
$query_get_user = sprintf("SELECT * FROM vb_user WHERE username='%s'", $HTTP_POST_VARS['username']);
$get_user = mysql_query($query_get_user, $connect) or die(mysql_error());
$row_get_user = mysql_fetch_assoc($get_user);
$totalRows_get_user = mysql_num_rows($get_user);

$password = md5(md5($HTTP_POST_VARS['password'] . $row_get_user['salt']));

mysql_select_db($database_connect, $connect);
$query_get_password = sprintf("SELECT * FROM vb_user WHERE password='%s'", $password);
$get_password = mysql_query($query_get_password, $connect) or die(mysql_error());
$row_get_password = mysql_fetch_assoc($get_password);
$totalRows_get_password = mysql_num_rows($get_password);

if($totalRows_get_password == 0) {
die('Password Error');
} 
Can someone help please?
Reply With Quote
  #2  
Old 08-09-2004, 10:50 PM
DrScion DrScion is offline
 
Join Date: Mar 2004
Posts: 6
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

My apologies, I miread one of the post I searched.

I have fixed my problem, and I will post the correct code for future reference...

PHP Code:
mysql_select_db($database_connect, $connect); 
$query_get_user = sprintf("SELECT * FROM vb_user WHERE username='%s'", $HTTP_POST_VARS['username']); 
$get_user = mysql_query($query_get_user, $connect) or die(mysql_error()); 
$row_get_user = mysql_fetch_assoc($get_user); 
$totalRows_get_user = mysql_num_rows($get_user); 

$password = md5(md5($HTTP_POST_VARS['password'])  $row_get_user['salt']); 

mysql_select_db($database_connect, $connect); 
$query_get_password = sprintf("SELECT * FROM vb_user WHERE password='%s'", $password); 
$get_password = mysql_query($query_get_password, $connect) or die(mysql_error()); 
$row_get_password = mysql_fetch_assoc($get_password); 
$totalRows_get_password = mysql_num_rows($get_password); 

if($totalRows_get_password == 0) { 
die('Password Error'); 
} 
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 07:40 PM.


Powered by vBulletin® Version 3.9.0
Copyright ©2000 - 2017, vBulletin Solutions Inc.