Zen Cart Logo
Forums / General Questions / Password MD5 HASH in DB.

Password MD5 HASH in DB.

Locked

Views: 7,803

Results 1 to 9 of 9
This thread is locked. New replies are disabled.
14 Mar 2007, 6:29 PM
#1
rabbie avatar

rabbie

New Zenner

Join Date:
Mar 2007
Posts:
4
Plugin Contributions:
0

Password MD5 HASH in DB.

Hello All,

I have a whole bunch of users that I want to import into the ZCart Database and I was wondering if anyone can help me out!

The problem I am having is that my other database stores the users passwords in plain text and Zcart stores the password in some sort of md5 hash...

I have tried every method I could find in google and anything I could use from the Zcart user setup php files and simply cannot work out how the passwords are being hashed.

Here is what I have so far (which is what I have taken from the user setup pages in osc:

<?php function zen_rand($min = null, $max = null) { static $seeded; if (!isset($seeded)) { mt_srand((double)microtime()*1000000);* $seeded = true; } if (isset($min) && isset($max)) { if ($min >= $max) { return $min; } else { return mt_rand($min, $max); } } else { return mt_rand(); } } $password = 'test1'; for ($i=0; $i<10; $i++) { $password .= zen_rand(); } $salt = substr(md5($password), 0, 2); $password = md5($salt . $plain) . ':' . $salt; echo $password; ?>

Now that generates the following password hash for the password test1: 6c8349cc7260ae62e3b1396831a8398f:4* 5 and I place that into the database in the same place as the user that I created using the Zcart signup page and it just wont let me login...

This is what the test1 password looks like for a user that I created using the standard method (the signup page): 0825f77f257b34bf43cfdcbccaa4622d:a* b

Thanks.

Rabbie.

14 Mar 2007, 7:16 PM
#2
merlinpa1969 avatar

merlinpa1969

Totally Zenned

Join Date:
Mar 2004
Posts:
13,031
Plugin Contributions:
4

Re: Password MD5 HASH in DB.

you can either setup ALL with a default password and manually change them by login in as customer,

OR you can set them up as a default then send a mass email out and request that the user resets their password

14 Mar 2007, 11:54 PM
#3
rabbie avatar

rabbie

New Zenner

Join Date:
Mar 2007
Posts:
4
Plugin Contributions:
0

Re: Password MD5 HASH in DB.

But why? Why is it sooooo hard to just come up with the right algorithm to reproduce the hash in the same way the cart does? Thats the way I want to do it !

15 Mar 2007, 1:10 AM
#4
merlinpa1969 avatar

merlinpa1969

Totally Zenned

Join Date:
Mar 2004
Posts:
13,031
Plugin Contributions:
4

Re: Password MD5 HASH in DB.

then have a blast

I offered you a solution,
sorry if it was to simple

15 Mar 2007, 2:05 AM
#5
rabbie avatar

rabbie

New Zenner

Join Date:
Mar 2007
Posts:
4
Plugin Contributions:
0

Re: Password MD5 HASH in DB.

Thanks Merlin! but whilst your solution is simple, the problem is that my customer requires that the password be the same as the current website!!!

I have finally found the solution thanks to another forum!!!

$password = 'test1';

$salt = substr(md5($password), 0, 2);

$password = md5($salt . $password) . ':' . $salt;

echo $password;

Now thats what I call simple!! I dont know why the bloody hell the random number generation crap is thrown into the mix! Probably to just confuse!

15 Mar 2007, 2:26 AM
#6
merlinpa1969 avatar

merlinpa1969

Totally Zenned

Join Date:
Mar 2004
Posts:
13,031
Plugin Contributions:
4

Re: Password MD5 HASH in DB.

random generation crap,

its called Security

15 Mar 2007, 2:29 AM
#7
rabbie avatar

rabbie

New Zenner

Join Date:
Mar 2007
Posts:
4
Plugin Contributions:
0

Re: Password MD5 HASH in DB.

Merlinpa1969:

its called Security

If I can generate a password without it, its called useless.

15 Mar 2007, 3:18 AM
#8
ajeh avatar

ajeh

Oba-san

Join Date:
Sep 2003
Location:
Ohio
Posts:
62,757
Plugin Contributions:
1

Re: Password MD5 HASH in DB.

And you could not write a simple file to utilize the existing password function to take the unencrypted password and just update the database? :unsure:

zen_encrypt_password

Select all customers_id and passwords
loop through the list
take old unencrypted password and encrypt with zen_encrypt_password
update password with new password for customers_id
skip to next customer

I am not sure why this would not work for you to use the built in Zen Cart function on this ...

15 Mar 2007, 11:08 AM
#9
scottb avatar

scottb

Zen Follower

Join Date:
Mar 2006
Location:
St. Louis area
Posts:
205
Plugin Contributions:
0

Re: Password MD5 HASH in DB.

I took a different approach.

I disabled the salt function and use plain MD5

//receive
$infoarray[9] = $_POST['customers_password'];     

//put
$password = md5($infoarray[9]);

I use a loop. The last list I imported was 1,281 users