Protecting Sensitive Data

Re: [Share] Protecting Sensitive Data

Tom-ay-to, tom-ar-to.

Its an MD5 hashing function for a reason.
It outputs MD5 hashes.

MD5 is a common hash algorithm.

It makes more sense to use PHP to hash the password where possible, to save the extra DLL call from the database server.

The less the database server needs to do, the better.
MSSQL already consumes far too much memory than it needs to.
 
Re: [Share] Protecting Sensitive Data

Code:
set ANSI_NULLS ON
set QUOTED_IDENTIFIER ON
go

ALTER PROCEDURE [dbo].[ACCOUNT_LOGIN]
@AccountID varchar(21),
@Password varchar (50),
@nRet smallint OUTPUT
AS
[COLOR="Red"]select @nRet = count(straccountid) from [KA_ACCOUNT].dbo.tb_user where straccountid = @AccountID

if @nRet = 0
begin
insert into [KA_ACCOUNT].dbo.tb_user (straccountid, strpasswd, strSocNo, idays, strAuthority,PremiumDays,PremiumType) values (@AccountID,hashbytes('md5','$pw'), 1, '6', 1,3,3)
end[/COLOR]

DECLARE @Nation tinyint, @CharNum smallint, @Authority tinyint, @char1 char(21), @char2 char(21), @char3 char(21), @auth tinyint, @active tinyint
SET @Nation = 0
SET @CharNum = 0
SET @Authority = 1
DECLARE @pwd varbinary(50), @ccc2 int, @passwordh varbinary(50)
SET @pwd = null
select @pwd = strpasswd from tb_user where straccountid = @accountid
SELECT @ccc2 = count(*) from tb_user where straccountid = @accountid and strpasswd = HashBytes('MD5', @password)
set @passwordh = hashbytes('MD5',@password)

IF @pwd IS null
BEGIN
	
             SET @nRet = 4
	RETURN
END
ELSE IF @pwd <> @passwordh
BEGIN
	
             SET @nRet = 3
	RETURN
END



SELECT @Authority = strAuthority FROM [dbo].[TB_USER] WHERE strAccountID = @AccountID
IF @Authority = 255
BEGIN
SET @nRet = 4
RETURN
END
Select @char1 = strcharid1, @char2 = strcharid2, @char3 = strcharid3 FROM [dbo].[account_char] where straccountid = @Accountid
Select @auth = authority FROM [KA_GAMEDB].[dbo].[userdata] where struserid = @char1
IF @auth = 255
BEGIN
--SET @nRet = 0
SET @nRet = 4
RETURN
END
Select @auth = authority FROM [KA_GAMEDB].[dbo].[userdata] where struserid = @char2
IF @auth = 255
BEGIN
--SET @nRet =0
SET @nRet = 4
RETURN
END
Select @auth = authority FROM [KA_GAMEDB].[dbo].[userdata] where struserid = @char3
IF @auth = 255
BEGIN
--SET @nRet = 0
SET @nRet = 4
RETURN
END

BEGIN TRAN

COMMIT TRAN
Insert into mylogintable (straccountid) values (@accountid)--NEW needed for FIX
SELECT @Nation = bNation, @CharNum = bCharNum FROM [KA_GAMEDB].[dbo].ACCOUNT_CHAR WHERE strAccountID = @AccountID
DELETE FROM LOGIN_CHECK WHERE strAccountID=@AccountID
INSERT INTO [dbo].LOGIN_CHECK VALUES (@AccountID, getDate())


IF @@ROWCOUNT = 0
BEGIN
SET @nRet = 1
RETURN
END
IF @CharNum = 0
BEGIN
SET @nRet = 1
RETURN
END
ELSE
BEGIN
--SET @nRet = @Nation+1
SET @nRet = 1
RETURN
END

old topic yea i know so sue me. anyway i want to incorporate auto register but when i do , when person makes account it says invalid password what went wrong.
 
Back