+ Reply to Thread
Page 2 of 3 FirstFirst 1 2 3 LastLast
Results 11 to 20 of 21

Thread: What format should i use to save password?

  1. #11
    Lazy Bum micky is a jewel in the rough micky is a jewel in the rough micky is a jewel in the rough micky is a jewel in the rough micky's Avatar
    Join Date
    Jul 2008
    Location
    India
    Posts
    683
    Blog Entries
    1
    Rep Power
    6

    Quote Originally Posted by jmurrayhead View Post
    It's a pretty good example, but not complete with information.

    I have a working sample at home that I won't mind sharing with you...just gotta give me about 10 hours :P
    okily dokily

    i'll wait patiently

  2. #12
    The Barnfather jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead's Avatar
    Join Date
    Mar 2008
    Location
    Washington, D.C.
    Posts
    2,347
    Blog Entries
    9
    Rep Power
    19

    Quote Originally Posted by micky View Post
    okily dokily

    i'll wait patiently
    Well, how else are you gonna wait?

    @RF - no hijacking...this isn't ASP Free
    jmurrayhead
    If you agree, give me rep. If my post helped you, click "Thanks".
    If you like it here...throw us a few bones to help support us.


  3. #13
    aka RF; RadioactiveFrog grae.uk will become famous soon enough grae.uk's Avatar
    Join Date
    Oct 2008
    Posts
    144
    Rep Power
    2

    Quote Originally Posted by jmurrayhead View Post
    Well, how else are you gonna wait?

    @RF - no hijacking...this isn't ASP Free
    Sorry Won't do it again.
    “There are two theories to argueing with women. Neither of them work! ” - Unknown

  4. #14
    Moderator don94403 is a jewel in the rough don94403 is a jewel in the rough don94403 is a jewel in the rough don94403's Avatar
    Join Date
    Mar 2008
    Location
    San Mateo, CA, USA
    Posts
    172
    Blog Entries
    8
    Rep Power
    5

    Quote Originally Posted by grae.uk View Post
    10hours...man that is a long drive home
    He's gonna stop off for a few beers on the way.

  5. #15
    The Barnfather jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead's Avatar
    Join Date
    Mar 2008
    Location
    Washington, D.C.
    Posts
    2,347
    Blog Entries
    9
    Rep Power
    19

    Quote Originally Posted by micky View Post
    okily dokily

    i'll wait patiently
    Here ya go, micky: Salted Password Hash - Code Samples
    jmurrayhead
    If you agree, give me rep. If my post helped you, click "Thanks".
    If you like it here...throw us a few bones to help support us.


  6. #16
    Lazy Bum micky is a jewel in the rough micky is a jewel in the rough micky is a jewel in the rough micky is a jewel in the rough micky's Avatar
    Join Date
    Jul 2008
    Location
    India
    Posts
    683
    Blog Entries
    1
    Rep Power
    6

    Quote Originally Posted by jmurrayhead View Post
    Thanx J
    works like a charm

  7. #17
    Lazy Bum micky is a jewel in the rough micky is a jewel in the rough micky is a jewel in the rough micky is a jewel in the rough micky's Avatar
    Join Date
    Jul 2008
    Location
    India
    Posts
    683
    Blog Entries
    1
    Rep Power
    6

    Quote Originally Posted by micky View Post
    Thanx J
    works like a charm
    J, can i do some changes in this code so that the salt created have only alphabets and numbers??

  8. #18
    The Barnfather jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead's Avatar
    Join Date
    Mar 2008
    Location
    Washington, D.C.
    Posts
    2,347
    Blog Entries
    9
    Rep Power
    19

    Quote Originally Posted by micky View Post
    J, can i do some changes in this code so that the salt created have only alphabets and numbers??
    The following line is what does it:

    Code:
    Convert.ToBase64String(buff)
    
    But why on earth would you want to do that? No one ever sees the salt, it is randomly generated to ensure more security.
    jmurrayhead
    If you agree, give me rep. If my post helped you, click "Thanks".
    If you like it here...throw us a few bones to help support us.


  9. #19
    Lazy Bum micky is a jewel in the rough micky is a jewel in the rough micky is a jewel in the rough micky is a jewel in the rough micky's Avatar
    Join Date
    Jul 2008
    Location
    India
    Posts
    683
    Blog Entries
    1
    Rep Power
    6

    Quote Originally Posted by jmurrayhead View Post
    The following line is what does it:

    Code:
    Convert.ToBase64String(buff)
    
    But why on earth would you want to do that? No one ever sees the salt, it is randomly generated to ensure more security.
    dont ask, its a dreadful story, u'll weep

    actually, i need to send user password if he forgets it and i have set password field to take only alpha numeric characters.

    so i m sending the salt to them!!
    am i doing something wrong??

  10. #20
    The Barnfather jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead has much to be proud of jmurrayhead's Avatar
    Join Date
    Mar 2008
    Location
    Washington, D.C.
    Posts
    2,347
    Blog Entries
    9
    Rep Power
    19

    Quote Originally Posted by micky View Post
    dont ask, its a dreadful story, u'll weep

    actually, i need to send user password if he forgets it and i have set password field to take only alpha numeric characters.

    so i m sending the salt to them!!
    am i doing something wrong??
    yes, it's dreadfully wrong micky lol. For one, sending passwords in emails is a very bad thing. You should setup a question/answer form where the user has to enter or select an existing question and provide the answer to it in order to reset their password. To do this, you would convert to lower case and hash their answer. Then, when they submit the form to reset their password, convert their answer to lower case and then hash it to compare against the hashed answer in the database.

    Emails can be intercepted and read by malicious users. It's a very bad thing and the password salt/hash was not designed to do this. For one, hashes are one-way.
    jmurrayhead
    If you agree, give me rep. If my post helped you, click "Thanks".
    If you like it here...throw us a few bones to help support us.


+ Reply to Thread
Page 2 of 3 FirstFirst 1 2 3 LastLast

Similar Threads

  1. Salted Password Hash
    By jmurrayhead in forum .Net Code Samples
    Replies: 14
    Last Post: November 19th, 2009, 11:06 AM
  2. Date Format Suggestion
    By icoombs in forum Suggestions & Feedback
    Replies: 1
    Last Post: July 14th, 2008, 07:41 AM
  3. Password Protected Tabs
    By AOG123 in forum Access Database Samples
    Replies: 3
    Last Post: June 13th, 2008, 03:20 PM
  4. Print out data on a letterhead format
    By Shem in forum .Net Development
    Replies: 3
    Last Post: May 22nd, 2008, 09:15 AM
  5. format currency to display by thousands
    By Rebelle in forum ASP Development
    Replies: 2
    Last Post: April 29th, 2008, 10:32 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts

SEO by vBSEO