[PHP/MYSQL] Help making Login script with hash passwords

Joined
Feb 7, 2011
Messages
3
Reaction score
0
I am trying to create a login script that would work on MMORPG game to log in with the game accounts on website.

Maybe its just for me , but it is quite hard to actually find working login script.
This is the register script code
And i dont understand what kind of passwords it logs in database.

Its md5 [hash] uses javascript file [ MD5.js ]
PHP:
<?php
			if($_GET['act'] == "register")
			{
				if(PhpCaptcha::Validate($_POST['CheckCode']))
				{
					mysql_select_db($mydbacc);
					$userid = trim($_POST['id']);
					$password=trim($_POST['pass']);
					$passretype=trim($_POST['retpass']);
					$hash=$_POST['hash'];
					if(!ereg("^[0-9a-z]{4,12}$",$userid))
					{
						echo "Only letters from \"a\" to \"z\" and numbers, lenght of 4 to 12 characters";
					}
					else
					{
						if($password == $passretype)
						{
							if(!ereg("^[0-9a-zA-Z]{4,12}$",$password))
							{
								echo "Only letters or numbers, lenght of 4 to 12 characters";
							}
							else
							{
								$res = mysql_query("select * from account where name = '".$userid."' order by id desc");
								if(mysql_num_rows($res) == 0)
								{
									mysql_query("insert into account (name,Password,Reg_date) values ('".$userid."','".$hash."','".date("y-m-d H:i:s", time())."')");
									echo "Account registered successfully.";
								}
								else
								{
									echo "Account Already exists in database.";
								}
							}
						}
						else
						{
							echo "Password not equal to Retyped Password.";
						}
					}
				}
				else
				{
					echo "Check Code is Wrong";
				}
			}
			?>
 
you dont understand i been using this script for ages , nobody has done anything , this is a MMORPG game registration , i cant use any register script , bcs it has to have hashed passwords , and i dont understand how the fuk they work. as i tryed alot of scripts that has MD5 / sha1

Thanks for your reply..

This http://pastebin.com/pPDsSNRL wont work on my database.
 
Last edited:
The example I gave uses MD5 to hash passwords.

PHP:
login($_POST['user'],md5($_POST['pass']));
The reason PHP's built-in md5() doesn't work is likely because the existing users were hashed using a different algorithm.

The "MD5.js" file seems (by it's name) that it has a function which should take a given string (like a password), and return the MD5 result of that string.

PHP's MD5 function is a much better way to do this. For one, JavaScript is client-side, and thus can be very insecure and/or unreliable. PHP is server-side so it works every time with no regard to the browser/ 3rd party client-side tools.

All you need to make the switch is these two pieces of information:
a.) Is the file MD5.js the same as PHP's md5() function? (it should be).
b.) What gets converted to an MD5 string? The password alone? a password and a salt? a username and password? We need to see the JavaScript that does this functionality. (probably not MD5.js).


The script will work for your database, just follow the instructions in the post and change these details to your own:
PHP:
//                 DB IP/address, DB user, DB pass, DB name
$mysqli = new mysqli('localhost','root','xxxxx','test_db');

Just because nobody did anything malicious yet doesn't mean it's secure.

I know for a fact the script you posted is insecure and might as well be asking for an attack.

If you must use your current registration script, I refuse to support or give assistance with that decision.
 
Last edited:
Back