如何使用PHP使用MD5加密此密码?

时间:2012-10-01 00:08:58

标签: php mysql encryption login md5

以下代码来自用PHP编写的登录脚本。它检查密码的数据库不使用MD5加密密码,但是当登录脚本检查数据库中的密码时,它正在检查原始密码而不加密。我熟悉md5()函数,但我如何将其合并到以下内容中:

<?php
session_start();

$username = $_POST['username'];
$password = $_POST['password'];

if ($username && $password) {
    $connect = mysql_connect("host", "user", "password") or die("Couldn't connect");
    mysql_select_db("dbname") or die("Couldn't find the database");

    $query = mysql_query("SELECT * FROM users WHERE username='$username'");
    $numrows = mysql_num_rows($query);

    if ($numrows != 0) {
        while ($row = mysql_fetch_assoc($query)) {
            $dbusername = $row['username'];
            $dbpassword = $row['password'];
        }

        if ($username == $dbusername && $password == $dbpassword) {
            echo "You're in! Click <a href='../member.php'>here</a> to enter the member page.";
            $_SESSION['username'] = $username;
        }else{
            echo "Incorrect password";
        }
    }else{
        die("That username does not exist.");
    }
}else{
    die("Please enter a valid username and password.");
}
?>

2 个答案:

答案 0 :(得分:5)

您应该检查并查询数据库以查找匹配项,而不是降低结果并在本地检查它们。随着说:

$password = md5($_POST['password']);

然后也改变:

SELECT * FROM users WHERE username='$username' AND password='$password'

但我还要看看使用PDO而不是将值直接放在SQL查询中。至少你应该使用mysql_real_escape_string来避免注射攻击。

答案 1 :(得分:0)

    $salt=sha1($postpassword);
    $arr= strlen($postpassword);
    $count=ceil($arr/2);
    $stringarr=str_split($postpassword,$count);
    $password1=hash("sha512", $stringarr['0']); 

    $password2=$salt . ( hash( 'whirlpool', $salt . $stringarr['1'] ) );
    return $password1.$password2;