Jump to content

[SOLVED] I Really Need A MD5 Auto Decrypter, Please Help!!


jamesxg1

Recommended Posts

Hello People,

 

Ok Basically With The Script Im Making The Admin View All The Customers Details,

 

But I When I View There Password From Admin Its MD5 Encrypted.

 

And I Dont Know How To Decrypt It :S,

 

When The User Registers The PHP Register Script Does Automatically MD5 Encode It And Store It To The DB But How Do I Temp De-Code It For My Viewing ?,

 

 

Many Thanks

 

James.

Link to comment
Share on other sites

You are really getting into account registration design theroy, mine is

 

1) Fill out registration form with captcha and their pw of their choice

2) Verify inputs in the form

3) In verification page send an email asking for email verification

4) They click email link account is now active

5) They login with the pw they originally selected

 

To recover pw a random 10 digit string is generated then md5ed and the non md5ed of it is emailed to the activated account

Link to comment
Share on other sites

And Is There Any Way Of Logging How Many Wrong Password They Enter ?.

 

Sure, if someone tries to login and fails, then store it in a column in the DB.

 

We would need some more information, and you're better off starting a new thread.

Link to comment
Share on other sites

Ok Well I Would Like To Go For The Idea Of Capturing The Password Before It Is MD5 En-Coded But How Would I Go About This So That The User Cannot See It And There Is No Vunrability ?

 

Nope. The moment you do anything with the non-MD5ed version of the password, you create potential vulnerabilites.

 

Note: Capitalizing every word puts you in the top 5 percentile of annoying when communicating in text.

Link to comment
Share on other sites

In a user system, an administrator account can directly perform any action that a user could and there is no need to know or have the user's password. Being logged in as an administrator should allow you access to an administrator's "control panel" page that you have written where you can select a user and view or modify any of that user's data.

Link to comment
Share on other sites

Yes Thats Exactly How My Registration System Is Except I Use 15 Character/Numberal Hash Code For There Lost Password.

 

 

And Is There Any Way Of Logging How Many Wrong Password They Enter ?.

 

Can you please stop posting each word beginning with a capital letter? Your making my eyes bleed.

Link to comment
Share on other sites

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.