Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

some passwords cause query to return results, but some do not

Posted on 2013-06-12
4
Medium Priority
?
229 Views
Last Modified: 2013-06-23
some passwords are sha1 other passwords are plain text
do not want to convert the plain text passwords because we want to see some passwords (I know it could be a security risk)

SELECT * FROM users WHERE (email='email' AND (pass='stravinsky1' or pass=SHA1('stravinsky1')))

but this does not work for
sha1(stravinsky1)
fc9bc17eea70a9c148869aca6414ddc4dc29e193

but when we convert password to sha1

SELECT * FROM users WHERE (email='email' AND (pass='fc9bc17eea70a9c148869aca6414ddc4dc29e193' or pass=SHA1('fc9bc17eea70a9c148869aca6414ddc4dc29e193')))
 no results returned (so user can not log in)


select sha1('12345')
8cb2237d0679ca88db6464eac60da96345513964

SELECT * FROM users WHERE (email='email2' AND (pass='8cb2237d0679ca88db6464eac60da96345513964' or pass=SHA1('8cb2237d0679ca88db6464eac60da96345513964')))

this query returns results

so password 12345 can be plain text or converted to sha1 and still work

so some passwords work using this query, others do not
0
Comment
Question by:rgb192
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 7

Expert Comment

by:Robert Saylor
ID: 39240807
I assume you are using php?

Why not use MD5 to encrypt it to the database then let php change it from cleartext to MD5 then compare apples to apples at MySQL?
0
 
LVL 15

Accepted Solution

by:
Jagadishwor Dulal earned 2000 total points
ID: 39240958
Try using sh1 to field name like:

SELECT * FROM users WHERE (email='email' AND (pass='stravinsky1' or SHA1(pass)='stravinsky1'))

Open in new window

0
 
LVL 111

Expert Comment

by:Ray Paseur
ID: 39244717
Please post a few rows of test data showing both the clear-text password and the SHA1 password.  Please tell us how you encoded the SHA1 fields -- was it done in PHP or in SQL?
0
 

Author Closing Comment

by:rgb192
ID: 39270435
password can be plaintext or hidden now

thanks
0

Featured Post

Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Load balancing is the method of dividing the total amount of work performed by one computer between two or more computers. Its aim is to get more work done in the same amount of time, ensuring that all the users get served faster.
In this blog post, we’ll look at how using thread_statistics can cause high memory usage.
In this video, Percona Solution Engineer Rick Golba discuss how (and why) you implement high availability in a database environment. To discuss how Percona Consulting can help with your design and architecture needs for your database and infrastr…
In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB. To learn more check out our webinar on MongoDB administration for MySQL DBA: https://www.percona.com/resources/we…
Suggested Courses

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question