DeveloperBarn Forums

DeveloperBarn

Programming & IT forum

What format should i use to save password?

This is a discussion on What format should i use to save password? within the MySQL forums, part of the Databases category; Hey fellas! I need to save user's password in a table. So whats the best way to save it in? ...

Go Back   DeveloperBarn Forums > Databases > MySQL

  #1  
Old October 25th, 2008, 06:43 AM
micky's Avatar
Lazy Bum
 
Join Date: Jul 2008
Location: India
Posts: 566
Rep Power: 4
micky has a spectacular aura aboutmicky has a spectacular aura aboutmicky has a spectacular aura about
Default What format should i use to save password?

Hey fellas!
I need to save user's password in a table.
So whats the best way to save it in?

RR advised me to use MD5, but i searched and found this article which says it can be hacked easily.
Cracking MySQL's MD5() function ... within seconds

Any ideas/advises??

VS.NET 2005

Micky
Reply With Quote
  #2  
Old October 25th, 2008, 07:02 AM
grae.uk's Avatar
aka RF; RadioactiveFrog
 
Join Date: Oct 2008
Posts: 144
Rep Power: 2
grae.uk will become famous soon enough
Default

Quote:
Originally Posted by micky View Post
Hey fellas!
I need to save user's password in a table.
So whats the best way to save it in?

RR advised me to use MD5, but i searched and found this article which says it can be hacked easily.
Cracking MySQL's MD5() function ... within seconds

Any ideas/advises??

VS.NET 2005

Micky
Hey Micky,
I always used to use md5(), haven't done much new php programming for a while now though so am not up to scratch with what is the best current method...however have you looked at the PHP: md5 - Manual page? There are some threads there talking about greater security...

Also...what are you securing access too? and how likely are people to want to crack it..that is something in my mind you have to weigh up with the time/money spent on securing it...

Just a thought, Let us know if you find something better

Graham.
__________________
“There are two theories to argueing with women. Neither of them work! ” - Unknown
Reply With Quote
  #3  
Old October 25th, 2008, 07:06 AM
micky's Avatar
Lazy Bum
 
Join Date: Jul 2008
Location: India
Posts: 566
Rep Power: 4
micky has a spectacular aura aboutmicky has a spectacular aura aboutmicky has a spectacular aura about
Default

thanx RF, i'll have a look
Reply With Quote
  #4  
Old October 25th, 2008, 07:09 AM
grae.uk's Avatar
aka RF; RadioactiveFrog
 
Join Date: Oct 2008
Posts: 144
Rep Power: 2
grae.uk will become famous soon enough
Default

Quote:
Originally Posted by micky View Post
thanx RF, i'll have a look
no worries, although just reread your post and you say VS.Net2005...sorry I presumed you were using PHP! Not sure my link will help afterall. Oh I do try!
Reply With Quote
  #5  
Old October 25th, 2008, 07:11 AM
micky's Avatar
Lazy Bum
 
Join Date: Jul 2008
Location: India
Posts: 566
Rep Power: 4
micky has a spectacular aura aboutmicky has a spectacular aura aboutmicky has a spectacular aura about
Default

Quote:
Originally Posted by grae.uk View Post
no worries, although just reread your post and you say VS.Net2005...sorry I presumed you were using PHP! Not sure my link will help afterall. Oh I do try!
lol
well the link might help, irrespective of development platrofm
Reply With Quote
  #6  
Old October 25th, 2008, 07:12 AM
grae.uk's Avatar
aka RF; RadioactiveFrog
 
Join Date: Oct 2008
Posts: 144
Rep Power: 2
grae.uk will become famous soon enough
Default

Quote:
Originally Posted by micky View Post
lol
well the link might help, irrespective of development platrofm
Guess the logic should be the same.
Reply With Quote
  #7  
Old October 25th, 2008, 09:50 AM
jmurrayhead's Avatar
The Barnfather
 
Join Date: Mar 2008
Real name: Jason
Location: Washington, D.C.
Posts: 1,964
Blog Entries: 8
Rep Power: 15
jmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud of
Default

Micky,

This all shouldn't be taken with a grain of salt...or perhaps, it should

I use SHA-1 with a password salt for extra security. I would look into going that route.
__________________
jmurrayhead
If you agree with me... click the icon!
If my post solved your problem, click the button in the lower right-hand corner of the post.

If you like it here...throw us a few bones to help
support us.

Join our Folding team: DeveloperBarn Folding

Reply With Quote
  #8  
Old October 27th, 2008, 03:45 AM
micky's Avatar
Lazy Bum
 
Join Date: Jul 2008
Location: India
Posts: 566
Rep Power: 4
micky has a spectacular aura aboutmicky has a spectacular aura aboutmicky has a spectacular aura about
Default

Quote:
Originally Posted by jmurrayhead View Post
Micky,

This all shouldn't be taken with a grain of salt...or perhaps, it should

I use SHA-1 with a password salt for extra security. I would look into going that route.
J, i searched and found this code!!
can u have a look and see if thats what u mean and if i shud use it

VB.NET Code Sample: Hashing Data

MySql
VS.NET 2005
Reply With Quote
  #9  
Old October 27th, 2008, 07:46 AM
jmurrayhead's Avatar
The Barnfather
 
Join Date: Mar 2008
Real name: Jason
Location: Washington, D.C.
Posts: 1,964
Blog Entries: 8
Rep Power: 15
jmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud ofjmurrayhead has much to be proud of
Default

It's a pretty good example, but not complete with information.

I have a working sample at home that I won't mind sharing with you...just gotta give me about 10 hours :P
Reply With Quote
  #10  
Old October 27th, 2008, 07:48 AM
grae.uk's Avatar
aka RF; RadioactiveFrog
 
Join Date: Oct 2008
Posts: 144
Rep Power: 2
grae.uk will become famous soon enough
Default

Quote:
Originally Posted by jmurrayhead View Post
It's a pretty good example, but not complete with information.

I have a working sample at home that I won't mind sharing with you...just gotta give me about 10 hours :P
10hours...man that is a long drive home
Reply With Quote
Reply

  DeveloperBarn Forums > Databases > MySQL

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads

Thread Thread Starter Forum Replies Last Post
Salted Password Hash jmurrayhead .Net Code Samples 14 November 19th, 2009 11:06 AM
[Suggestion] Date Format Suggestion icoombs Suggestions & Feedback 1 July 14th, 2008 07:41 AM
Password Protected Tabs AOG123 Access Database Samples 3 June 13th, 2008 03:20 PM
Print out data on a letterhead format Shem .Net Development 3 May 22nd, 2008 09:15 AM
format currency to display by thousands Rebelle ASP Development 2 April 29th, 2008 10:32 PM


All times are GMT -4. The time now is 11:22 PM.


Copyright ©2008-2010, DeveloperBarn

Content Relevant URLs by vBSEO 3.3.2