[PHP] Password HASH - MD5.Salt

gooby pls
Decennium
Joined
Mar 22, 2008
Messages
830
Reaction score
177
Well, I have successfully merged a register page to register an account in MSSQL and then the same account into MySQL, but MySQL has a special encryption, and I am having problems Hashing the damn password...
Here is the code, I have tried too many different ways to hash a string, but failed...

PHP:
$pass = stripslashes($_POST['pass']);
function makePassword( $pass ) {
    $chars = "abcdefghijklmnopqrstuvwxyz" ;
    $chars .= "ABCDEFGHIJKLMNOPQRSTUVWXYZ" ;
    $chars .= "0123456789";
    $len = strlen($chars);
    $salt = '';
    mt_srand(10000000 * (double) microtime());
    for ($i = 0; $i < 32; $i ++) {
        $salt .= $chars[mt_rand(0, $len -1)];
    }
    return md5( $password . $salt ) . ':' . $salt ;
}
echo makePassword( $pass ) ;

I hope someone can help fast, because its pretty urgent.



Thanks in advance!
 
What are you trying to do? A salt must be reproducible if you are ever to hope to compare a given password to the stored hash.

Also, thing such as

Code:
md5({username}.{5 letter random code}.{password});

are more than secure enough. Rainbow tables are ineffective against even basic salts. And you can change it up however you like so nobody truly knows (until they see your code) what the data in the password field actually represents.
 
What are you trying to do? A salt must be reproducible if you are ever to hope to compare a given password to the stored hash.

Also, thing such as

Code:
md5({username}.{5 letter random code}.{password});
are more than secure enough. Rainbow tables are ineffective against even basic salts. And you can change it up however you like so nobody truly knows (until they see your code) what the data in the password field actually represents.

It actually represents a password from Joomla website.
I linked Joomla and game register to the same form, but I can't get the non coded password, to save into the table already encrypted.


http://fate.ulti.nl/game/makejoomlapassword.php
This website shows a the word compaq as MD5.Salt

and its code is
PHP:
<?

$pass = 'compaq' ;
function makePassword( $pass ) {
    $chars = "abcdefghijklmnopqrstuvwxyz" ;
    $chars .= "ABCDEFGHIJKLMNOPQRSTUVWXYZ" ;
    $chars .= "0123456789";
    $len = strlen($chars);
    $salt = '';
    mt_srand(10000000 * (double) microtime());
    for ($i = 0; $i < 32; $i ++) {
        $salt .= $chars[mt_rand(0, $len -1)];
    }
    return md5( $password . $salt ) . ':' . $salt ;
}
echo makePassword( $pass ) ;
?>

Which is the exact one I must use to store the login password into the Joomla database.
 
Everything is working, I only need to know how in the world I make a password value from a query be hashed...

I have everything else working, just need the password that will be inputted into the MySQL database be encrypted.
 
Last edited by a moderator:
You hash it before sending it to the DB. The real password is never sent there, just the hash version. Then when they log in, you hash the POST['pass'], and match it with the one on the DB that's already hashed. If it matches, let them in. Else, wrong user or pass.
 
You hash it before sending it to the DB. The real password is never sent there, just the hash version. Then when they log in, you hash the POST['pass'], and match it with the one on the DB that's already hashed. If it matches, let them in. Else, wrong user or pass.

Yes I know this...
I have problems hashing it! I don't know how to hash it before sending it, and I must use the algorithms geven before, other ways it wont work...
 
This,
PHP:
for ($i = 0; $i < 32; $i ++) {
        $salt .= $chars[mt_rand(0, $len -1)];
    }
will make a random string every time, as you know. A salt, as Merlin said, needs to be the same for each password. It cannot be random. You can make the salt unique to an unchanging string, such as the user or a piece of the pass before it's encrypted. It's even better if you just write some gibberish and add it in there. Just don't let anyone know what the salt is.

I think you need to start the table over, unfortunately, because it looks impossible to get the same salt again. It needs to be reproducible, as Merlin stated.

Edit: Here, try a function more like this:
PHP:
$pass = 'compaq' ;
function makePassword( $pass ) 
{
    return md5( 'Gibberish*123'.$pass.'Ooo, two salts!' );
}
echo makePassword( $pass ) ;
?>
 
Last edited:
This,
You can make the salt unique to an unchanging string, such as the user or a piece of the pass before it's encrypted. It's even better if you just write some gibberish and add it in there. Just don't let anyone know what the salt is.

My favorite was the one I made a while back. It used a checksum + a parity bit of the username along with a 10 character string randomly generated seeded with the sum of the ascii values of the username mod a prime with the password followed by the md5 of the username. Let's just say there aren't any rainbow tables in the world that are going to break that :p, ever.

The entire point of a salt is to

1. Increase hash crypto strength by making the actual data hashed a secret so that hackers, even if they guess the password (which might be say.. 6 characters long) won't be able to verify that it's correct.

2. Guarantee that no two hashes of passwords, even if they're identical to different users, will ever be the same in the database.

That's good in case someone ever dumps your database and notices two people have the same password. If you got a DB with thousands of password hashes and 5 were the same, you'd wanna crack that top priority because you get 5 for the price of 1. Not a good idea to let that happen.. ever.
 
I don't need to reproduce the password, since the Joomla actually works like that!
I got the algorithms from the Joomla register, and now want to put it into the game register.

I just need to know how in the world I input a password using the hash given before...


Thanks for the effort!
 
I don't need to reproduce the password, since the Joomla actually works like that!
I got the algorithms from the Joomla register, and now want to put it into the game register.

I just need to know how in the world I input a password using the hash given before...


Thanks for the effort!

You aren't making any sense.
 
Back