by Chris Root
The PHP crypt function is a one-way encryption function that lets you confirm that an entered password matches a stored encrypted one -- without having to decrypt anything. Chris Root explains how it works.
Protecting user names and passwords, not to mention financial or other personal information, can be a difficult job for any webmaster. Unfortunately there are an awful lot of people out there with nothing better to do than break into your system and steal information, or just wreak havok. One of the tools of the trade for information protection is encryption. There is a built-in function of the PHP language called crypt() which is easy to use and can help you secure information you want to protect.
Crypt is a one-way encryption function. You may wonder then, "What good is it if I can't decrypt what I have encrypted?" The answer is simple. In PHP, crypt can be used to confirm that, for example, an entered password matches a stored encrypted one.
Here is how it works: crypt accepts two arguments and returns an encrypted string. The first argument is the string you wish to encrypt. Use the trim function to ensure that whitespace on either side of the string is stripped away, just to make everything cleaner. The second argument is the encryption "salt," which is a string that is used on which to base the encryption. This is an optional parameter that, if not supplied, will be randomly generated by the function. Here is an example:
Code: Select all
$crypted_pass = crypt($password);Code: Select all
//$pass_entered_from_login is the user entered password
//$crypted_pass is the encrypted password from the
//database or file
if(crypt($pass_entered_from_login,$crypted_pass)) == $crypted_pass)
{
echo("Welcome to my web site.")
}This allows you to confirm the password without decrypting it, since all you really need to know is if it matches the user's input. You can use this for any information that is short (8 charaters on some systems) and needs to be confirmed but not decrypted. User information like passwords are the most common target for this function.
Crypt uses standard MD5 encryption but can also use DES or other encryption as available. Information on the types of encryption that is available on your system can be viewed through constants set in PHP. Check for which encryption is supported by using the following code.
Code: Select all
echo("DES is " . CRYPT_STD_DES."<br>Extended DES is ".
CRYPT_EXT_DES."<br>MD5 is "CRYPT_MD5.
"<br>BlowFish is ".CRYPT_BLOWFISH");DES is 1
Extended DES is 1
MD5 is 1
BlowFish is 0
If any of these is "0" then it is not supported. Each of these algorithms use a different salt. MD5 uses 12 characters, DES uses 2. Also beware that some operating systems truncate a string that is larger than 8 characters before encrypting it. You should test this in your comparison script on the system that you intend to use it just in case. You can also check CRYPT_SALT_LENGTH to determine the default salt length. It may be 2 or 12 depending on the encryption that is used.
It is not recommended that you use an automatically generated salt if you will be calling crypt repeatedly, such as in a loop. The same salt will be used, which will compromise security.
First let's set up a form for entering a username and password to add a new user into the system. Let's use an example of a form for an admin interface to administer a Company X product database for Web display.
Code: Select all
<html>
<head>
<title>Company X Products Admin Application Add New User </title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
</head>
<body>
<h1>Administration Interface login: Add new User</h1>
<form name="form1" method="post" action="admin_login_newuserbe.php">
<p>
<input name="uname" type="text" id="uname" size="8" maxlength="8">
<strong>Enter User Name</strong>
<br>
<input name="pword" type="password" id="pword" size="8" maxlength="8">
<strong>Enter Password</strong>
<br><input type="submit" name="Submit" value="Add">
</p>
</form>
</body>
</html>Code: Select all
if(empty($_POST[pword]) || empty($_POST[uname]))
{
echo "<html><head></head>
<body><h1>You must enter both a username and password.
<a href = \"admin_login_newuser.html\">Try Again?
</a></h1></body></html>";
}Code: Select all
else
{
$pwrd = crypt(trim("$_POST[pword]"));
$user = trim("$_POST[uname]");
//Code for accessing you database or flat file goes here.You could also set up a way to track the number of times a user attempted to log in within a certain period of time if you wished. Options to reset passwords and have passwords emailed to the user are also good add-ons. Of course keep in mind that wherever you store an unencrypted password, it had better be secure. If the information you are protecting is something like credit card information, it's even more important.
Code: Select all
//the array $row is from the database that holds our information.
if(crypt($pwrd,$row[pword]) == $row[pword])
{
session_start();//start the new session
$sesid = session_id();//get the session id
$_SESSION[logged] = TRUE;//set a session id to check if this user is logged in
header("location: chooser.php?id=$sesid");//redirect the user to the admin interface page
break;
}
else//whoops no match but be nice and let them try again.
{
echo "<html><head></head>
<body><h1>Sorry No Passord matches.
</h1><a href = \"admin_login.html\">Try Again?</a></body></html>";
break;
}You also have the option of using the htaccess and htpasswd file if you are using the Apache Web server. Make sure to consult any documentation for your server for more information. Another good general net security resource is available at [url="http://www.net-security.org/"]http://www.net-security.org/[/url]. Always keep up with the latest security updates and bulletins for any software you use on your site and apply the available patches promptly.
There are other encryption functions or add ons for PHP as well. Such as md5() or a two way PHP extension called Mcrypt. A good source for information about these or other PHP functions and features is in the PHP manual. You can access the PHP manual on line at [url="http://us2.php.net/manual/en/index.php"]http://us2.php.net/manual/en/index.php[/url] or through the PHP Freaks web site [url="http://www.phpfreaks.com/"]http://www.phpfreaks.com/[/url].
Conclusion
Using crypt we have made password validation secure and easy. There was no need to ever expose the real password and the logged in user is now on their way to doing some work. Always consider all security measures available when you have important information to protect.
[url="http://www.devshed.com/c/a/PHP/Using-the-PHP-Crypt-Function/"]source: DevShed[/url]

