NameSilo

Secure login

SpaceshipSpaceship
Watch

web guru

Established Member
Impact
0
I have written a login script and I think I have made it as secure as possible - check session id, user ip, encrypted passwords along with a few other methods. But I have used MD5 to encrypt my passwords. This is a one way encryption method, thus even the sys admin doesent know what your password is. But what if a user forgets hi/her password. How could I go about finding it out. I was thinking about storing the password somewhere else, but then what would be the point in encrypting it in the first place? Ay one got any ideas how to go about this or even any other ideas of encrypting passwords??
 
0
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
GoDaddyGoDaddy
secret question :)

ur get the user to enter there user name and it sends an email with the pw in it to the adress in the user profile :)
 
0
•••
I think you would probably want to have something like a forgot password feature and have it generate a random password and send it to the email address you have on file and of course it would need to update your system so that randomly generated password was now their password until they login and change it.

That is probably quite a bit more coding, but I think that would be about your best option if you're using one way encryption like MD5. Most, if not all of the software that I've used, which uses MD5 for passwords seems to have a feature that works this way.

Another option would be to use RC4 if you wanted a way to encrypt and decrypt passwords.
 
0
•••
Thanks dead thats a great idea!!
 
0
•••
Can I get a copy of this code, I would like to encrypt it into my own website!

Thanks! :D

P.S. Your script sounds great!
 
0
•••
Originally posted by $D$2
Can I get a copy of this code, I would like to encrypt it into my own website!

Thanks! :D

P.S. Your script sounds great!

why dont u make it urself ;)
 
0
•••
0
•••
Dynadot — .com TransferDynadot — .com Transfer
CatchedCatched

We're social

Escrow.com
Spaceship
Rexus Domain
CryptoExchange.com
Domain Recover
CatchDoms
DomainEasy — Payment Flexibility
DomDB
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.
Back