KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
1) How do you create secure Blowfish hashes of passwords with crypt()? $hash = crypt('somePassword', '$2a$07$nGYCCmhrzjrgdcxjH$'); 1a) What is the significance of "$2a"? Does it just indicate that the Blowfish algorithm should be used? 1b) What is the significance of "$07"? Does a higher value imply a more secure hash? 1c) What is the significance of "$nGYCCmhrzjrgdcxjH$"? Is this the salt that will be used? Should this be randomly generated? Hard-coded? 2) How do you store Blowfish hashes? echo $hash; //Output: $2a$07$nGYCCmhrzjrgdcxjH$$$$.xLJMTJxaRa12DnhpAJmKQw.NXXZHgyq 2a) What part of this should be stored in the database? 2b) What data type should be used for the column (MySQL)? 3) How should one verify a login attempt?
Tags (comma-separated)
Save Edits
Cancel