doupeng3501 2015-10-05 22:59
浏览 184

将password_hash生成的两个哈希值与一个密码进行比较

So I store users password in database after hashed by password_hash() (php 5.5+). and then verify user when logging in using password_verify(). but now i want to also store password on users browser with cookies. i hash the same password using password_hash but this time the second part of hash is obviously different. (salt)

because of that, two hashes (the one in database and the one in cookie) are NOT equal. how do i verify them then???

  • 写回答

2条回答 默认 最新

  • doufang1954 2015-10-05 23:28
    关注

    store user credential on cookie is high risk.

    If you store hashes password on database so you only need pass username and password then will hashes from other file and match it into your database.

    ex. login.php post username and password

    usercheck.php md5(password) and check it into database which already hashes password

    评论

报告相同问题?

悬赏问题

  • ¥15 虚幻5 UE美术毛发渲染
  • ¥15 CVRP 图论 物流运输优化
  • ¥15 Tableau online 嵌入ppt失败
  • ¥100 支付宝网页转账系统不识别账号
  • ¥15 基于单片机的靶位控制系统
  • ¥15 真我手机蓝牙传输进度消息被关闭了,怎么打开?(关键词-消息通知)
  • ¥15 装 pytorch 的时候出了好多问题,遇到这种情况怎么处理?
  • ¥20 IOS游览器某宝手机网页版自动立即购买JavaScript脚本
  • ¥15 手机接入宽带网线,如何释放宽带全部速度
  • ¥30 关于#r语言#的问题:如何对R语言中mfgarch包中构建的garch-midas模型进行样本内长期波动率预测和样本外长期波动率预测