Ignore:
Timestamp:
Jan 31, 2010, 9:41:08 AM (15 years ago)
Author:
george
Message:
  • Upraveno: Posílení bezpečnosti hesel pomocí připojování náhodných dat Salt k hashovanému heslu.
  • Opraveno: Mazání úloh exportu, které odkazují na již smazaný export.
File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/includes/global_function.php

    r307 r308  
    208208  if(isset($_SESSION['User']) and ($_SESSION['User'] <> '') and ($_SESSION['UserID'] != ''))
    209209  {
    210     //  $User = $_SESSION['User'];
     210    // $User = $_SESSION['User'];
    211211    $Pass = $_SESSION['Pass'];
    212     $Line = mysql_fetch_array($Database->SQLCommand('SELECT * FROM user WHERE ID = '.$_SESSION['UserID'].'
    213       AND GM >= '.$Licence.' AND pass = sha1("'.$Pass.'")'));
    214     //  echo "SELECT * FROM user WHERE ID = ".$_SESSION['UserID']." AND GM <= $Licence AND pass = '$Pass'";
     212    $Line = mysql_fetch_array($Database->SQLCommand('SELECT * FROM user WHERE ID = '.$_SESSION['UserID'].' AND GM >= '.$Licence.' AND pass = sha1(CONCAT(sha1("'.$Pass.'"), Salt))'));
    215213    return($Line);
    216214  } else
     
    547545}
    548546
     547function GetPasswordSalt()
     548{
     549  return(substr(sha1(mt_rand()), 0, 8));
     550}
    549551
    550552?>
Note: See TracChangeset for help on using the changeset viewer.