DeveloperBarn Forums

DeveloperBarn

Programming & IT forum

What format should i use to save password?

This is a discussion on What format should i use to save password? within the MySQL forums, part of the Databases category; Originally Posted by jmurrayhead It's a pretty good example, but not complete with information. I have a working sample at ...

Go Back   DeveloperBarn Forums > Databases > MySQL


Reply

 

LinkBack Thread Tools Display Modes
  #11  
Old October 27th, 2008, 07:50 AM
micky's Avatar
Lazy Bum
 
Join Date: Jul 2008
Location: India
Posts: 566
Rep Power: 4
micky has a spectacular aura aboutmicky has a spectacular aura aboutmicky has a spectacular aura about
Default

Quote:
Originally Posted by jmurrayhead View Post
It's a pretty good example, but not complete with information.

I have a working sample at home that I won't mind sharing with you...just gotta give me about 10 hours :P
okily dokily

i'll wait patiently
Reply With Quote
  #12  
Old October 27th, 2008, 07:53 AM
jmurrayhead's Avatar
The Barnfather
 
Join Date: Mar 2008
Real name: Jason
Location: Washington, D.C.
Posts: 1,964
Blog Entries: 8
Rep Power: 15
jmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud of
Default

Quote:
Originally Posted by micky View Post
okily dokily

i'll wait patiently
Well, how else are you gonna wait?

@RF - no hijacking...this isn't ASP Free
__________________
jmurrayhead
If you agree with me... click the icon!
If my post solved your problem, click the button in the lower right-hand corner of the post.

If you like it here...throw us a few bones to help
support us.

Join our Folding team: DeveloperBarn Folding

Reply With Quote
  #13  
Old October 27th, 2008, 07:55 AM
grae.uk's Avatar
aka RF; RadioactiveFrog
 
Join Date: Oct 2008
Posts: 144
Rep Power: 2
grae.uk will become famous soon enough
Default

Quote:
Originally Posted by jmurrayhead View Post
Well, how else are you gonna wait?

@RF - no hijacking...this isn't ASP Free
Sorry Won't do it again.

Comments on this post
jmurrayhead agrees:
__________________
“There are two theories to argueing with women. Neither of them work! ” - Unknown
Reply With Quote
  #14  
Old October 27th, 2008, 02:43 PM
don94403's Avatar
Moderator
 
Join Date: Mar 2008
Location: San Mateo, CA, USA
Posts: 146
Blog Entries: 8
Rep Power: 4
don94403 has a spectacular aura aboutdon94403 has a spectacular aura aboutdon94403 has a spectacular aura about
Default

Quote:
Originally Posted by grae.uk View Post
10hours...man that is a long drive home
He's gonna stop off for a few beers on the way.
Reply With Quote
  #15  
Old October 27th, 2008, 06:08 PM
jmurrayhead's Avatar
The Barnfather
 
Join Date: Mar 2008
Real name: Jason
Location: Washington, D.C.
Posts: 1,964
Blog Entries: 8
Rep Power: 15
jmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud of
Default

Quote:
Originally Posted by micky View Post
okily dokily

i'll wait patiently
Here ya go, micky: Salted Password Hash - Code Samples

Comments on this post
micky agrees: Thanked Post
Reply With Quote
The Following User Says Thank You to jmurrayhead For This Useful Post:
micky (October 29th, 2008)
  #16  
Old October 29th, 2008, 05:04 AM
micky's Avatar
Lazy Bum
 
Join Date: Jul 2008
Location: India
Posts: 566
Rep Power: 4
micky has a spectacular aura aboutmicky has a spectacular aura aboutmicky has a spectacular aura about
Default

Quote:
Originally Posted by jmurrayhead View Post
Thanx J
works like a charm
Reply With Quote
  #17  
Old November 4th, 2008, 05:51 AM
micky's Avatar
Lazy Bum
 
Join Date: Jul 2008
Location: India
Posts: 566
Rep Power: 4
micky has a spectacular aura aboutmicky has a spectacular aura aboutmicky has a spectacular aura about
Default

Quote:
Originally Posted by micky View Post
Thanx J
works like a charm
J, can i do some changes in this code so that the salt created have only alphabets and numbers??
Reply With Quote
  #18  
Old November 4th, 2008, 08:35 AM
jmurrayhead's Avatar
The Barnfather
 
Join Date: Mar 2008
Real name: Jason
Location: Washington, D.C.
Posts: 1,964
Blog Entries: 8
Rep Power: 15
jmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud of
Default

Quote:
Originally Posted by micky View Post
J, can i do some changes in this code so that the salt created have only alphabets and numbers??
The following line is what does it:

Code:
Convert.ToBase64String(buff)
But why on earth would you want to do that? No one ever sees the salt, it is randomly generated to ensure more security.
Reply With Quote
  #19  
Old November 4th, 2008, 08:41 AM
micky's Avatar
Lazy Bum
 
Join Date: Jul 2008
Location: India
Posts: 566
Rep Power: 4
micky has a spectacular aura aboutmicky has a spectacular aura aboutmicky has a spectacular aura about
Default

Quote:
Originally Posted by jmurrayhead View Post
The following line is what does it:

Code:
Convert.ToBase64String(buff)
But why on earth would you want to do that? No one ever sees the salt, it is randomly generated to ensure more security.
dont ask, its a dreadful story, u'll weep

actually, i need to send user password if he forgets it and i have set password field to take only alpha numeric characters.

so i m sending the salt to them!!
am i doing something wrong??
Reply With Quote
  #20  
Old November 4th, 2008, 08:47 AM
jmurrayhead's Avatar
The Barnfather
 
Join Date: Mar 2008
Real name: Jason
Location: Washington, D.C.
Posts: 1,964
Blog Entries: 8
Rep Power: 15
jmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud of
Default

Quote:
Originally Posted by micky View Post
dont ask, its a dreadful story, u'll weep

actually, i need to send user password if he forgets it and i have set password field to take only alpha numeric characters.

so i m sending the salt to them!!
am i doing something wrong??
yes, it's dreadfully wrong micky lol. For one, sending passwords in emails is a very bad thing. You should setup a question/answer form where the user has to enter or select an existing question and provide the answer to it in order to reset their password. To do this, you would convert to lower case and hash their answer. Then, when they submit the form to reset their password, convert their answer to lower case and then hash it to compare against the hashed answer in the database.

Emails can be intercepted and read by malicious users. It's a very bad thing and the password salt/hash was not designed to do this. For one, hashes are one-way.
Reply With Quote
Reply

  DeveloperBarn Forums > Databases > MySQL

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads

Thread Thread Starter Forum Replies Last Post
Salted Password Hash jmurrayhead .Net Code Samples 14 November 19th, 2009 11:06 AM
[Suggestion] Date Format Suggestion icoombs Suggestions & Feedback 1 July 14th, 2008 07:41 AM
Password Protected Tabs AOG123 Access Database Samples 3 June 13th, 2008 03:20 PM
Print out data on a letterhead format Shem .Net Development 3 May 22nd, 2008 09:15 AM
format currency to display by thousands Rebelle ASP Development 2 April 29th, 2008 10:32 PM


All times are GMT -4. The time now is 05:14 PM.


Copyright ©2008-2010, DeveloperBarn

Content Relevant URLs by vBSEO 3.3.2