Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

Encryption using crypt()

I'm currently doing a very safe login system, but I'm new to the crypt() function and need some quick assistance.

I used crypt() to encrypt the password string during signup and saved it to the database. However, how will I be able to decrypt the key during login? Or how am I supposed to do otherwise? Or would it be possibly to do some magic with the submitted password string to compare it to the encrypted key in the database?

like image 437
Nikkster Avatar asked Sep 27 '26 20:09

Nikkster


1 Answers

crypt() doesn't encrypt passwords, it hashes them. The fundamental difference is, you can't get hashed passwords back (think of hash browns - if you have hash browns, you can't get the potatoes back).

So you apply the same function to the input and compare its result to the value stored in the database:

$stored_pw = get_hashed_password_from_db($_POST['username']);
crypt($_POST['password'], $stored_pw) == $stored_pw

Read the documentation on crypt() to understand the "magic" behind the code above works.

like image 144
NullUserException Avatar answered Sep 30 '26 12:09

NullUserException



Donate For Us

If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!