Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


How to compare ms sql hashbytes results within vb6

Posted on 2016-11-06
Medium Priority
Last Modified: 2016-11-09
We are using ms sql hashbytes to encrypt a password column.  What would be the best way to retrieve the value, compare and give the correct results to the user?  In ssms we can 'IF HASHBYTES('SHA1','ExpertExchange') = HASHBYTES('SHA1',@SuppliedPassword) ', but how can we do this compare within vb6? vb6 has an equivalent to hashbyte function?
Question by:rayluvs
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3

Author Comment

ID: 41876283

found this vb code to see how to incorporate what want.

Works fine for Hash ansi & unicode but not for sha1, it gies an error on 'SHA1Hash.HashFile' like it doesn't exist (see pix below)

How do we get file?
Do we need it?
Does the apps return the same value as SQL HASHBYTE function (see below example)?

SELECT HASHBYTES('SHA1', 'ExpertExchange')


(see code attached)
LVL 35

Expert Comment

ID: 41876715
How do we get file?
Depends on your application.

Do we need it?
Depends on your application.

Does the apps return the same value as SQL HASHBYTE function (see below example)?
Maybe, the image does not show any hash handling.

p.s. IF HASHBYTES('SHA1','ExpertExchange') = HASHBYTES('SHA1',@SuppliedPassword) is nonsense. Don't store passwords. It's insecure by design. Store a salted hash instead of it.
LVL 32

Accepted Solution

Pawan Kumar earned 2000 total points
ID: 41876717
So if it working in SSMS then you can create a stored Procedure with a Parameter called User Name call that from VB code.


CREATE PROC CheckPwduser
	@SuppliedPassword VARCHAR(100)

	IF HASHBYTES('SHA1','ExpertExchange') = HASHBYTES('SHA1',@SuppliedPassword) 
			SELECT 1 as Output
			SELECT 0  as Output


Open in new window

So if you get value 0 then you have invalid password other wise valid password.

Hope it helps !

Author Comment

ID: 41876741

"p.s. IF HASHBYTES('SHA1','ExpertExchange') = HASHBYTES('SHA1',@SuppliedPassword) is nonsense. Don't store passwords. "

We placed this for references since we started are working with HASHBYTES function SQL and wanted to know how to do it in vb6.

"How do we get file?
Depends on your application."

The apps is not ours, we found it  and ran and it gave us that message, so we thought an expert can assist on the message

"Do we need it?
Depends on your application."

Same answer, we thought that by showing he code to EE, it would help helping us; again, it's not our code.

Can you take a look at the code? (maybe you can detect the problem)

"Store a salted hash instead of it."

Please provide an example of the process.

Pawan Kumar Khowal,

Thanx, if working in SSMS that would be great, however we are working with vb6 (unless we can pass the users password to SQL and compre and return the resulat back to the vb6 apps?).

In essence, what we want if to compare the HASBYTE value saved in the MS SQL table against the resulting HASHBYTE value in the vb6 apps.  We think our process would be something like this with the code:

1. In the vb6 code ask the user for the password.
2. Convert that value to the HASHBYTE value. <-- (THIS IS WHERE WE WANT ASSISTANCE)
3. Read the SQL table and bring the HASHBYTE value already saved for comparison
4. Compare the users entry password's HASHBYTE value to what is saved in the SQL table.

Author Closing Comment

ID: 41881402
For some reason didn't quite read your entry.  We always re-read the entire question prior deleting one that there is no answer to.  Doing that we slowed down on your entry and modified some and it worked!  So pleasa excuse the delay and thanx!

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Since upgrading to Office 2013 or higher installing the Smart Indenter addin will fail. This article will explain how to install it so it will work regardless of the Office version installed.
This article describes how you can use Custom Document Properties to store settings and other information in your workbook so that they will be available the next time you open the workbook.
As developers, we are not limited to the functions provided by the VBA language. In addition, we can call the functions that are part of the Windows operating system. These functions are part of the Windows API (Application Programming Interface). U…
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…
Suggested Courses

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question