jmurrayhead
If you agree, give me rep. If my post helped you, click "Thanks".
If you like it here...throw us a few bones to help support us.
Here ya go, micky: Salted Password Hash - Code Samples
jmurrayhead
If you agree, give me rep. If my post helped you, click "Thanks".
If you like it here...throw us a few bones to help support us.
jmurrayhead
If you agree, give me rep. If my post helped you, click "Thanks".
If you like it here...throw us a few bones to help support us.
yes, it's dreadfully wrong micky lol. For one, sending passwords in emails is a very bad thing. You should setup a question/answer form where the user has to enter or select an existing question and provide the answer to it in order to reset their password. To do this, you would convert to lower case and hash their answer. Then, when they submit the form to reset their password, convert their answer to lower case and then hash it to compare against the hashed answer in the database.
Emails can be intercepted and read by malicious users. It's a very bad thing and the password salt/hash was not designed to do this. For one, hashes are one-way.
jmurrayhead
If you agree, give me rep. If my post helped you, click "Thanks".
If you like it here...throw us a few bones to help support us.
Bookmarks