From: Aaron Turner Date: 2008-11-21T03:46:29+09:00 Subject: Re: create a md5 / md5 passwd with a salt On Thu, Nov 20, 2008 at 10:21 AM, Peter Woodsky wrote: > Hi list > > This problem is so above me my head is swimming. > > I have a forum software that recently changed the way passwords were > stored. I use a ruby script to update the user table when the user > changes the password but my script no longer works so I hope someone > here can help or point me in the right direction. > > The forum now uses this format for storing passwords md5(md5(PASSWORD) . > salt) where previously it was md5(PASSWORD) which was pretty easy to > deal with. > > This is what I used before: > > require 'cgi' > cgi = CGI.new > require 'digest/md5' > user_pwd = hash_class.hexdigest("#{password}") > end user_pwd = Digest::MD5.hexdigest(Digest::MD5.hexdigest(password) + salt) I will point out this though: for this to work, somewhere you need to store the PLAIN TEXT salt in the DB. Usually this is done by pre-pending the salt to the hashed pasword like this: user_pwd = salt + Digest::MD5.hexdigest(Digest::MD5.hexdigest(password) + salt) Or it might be stored in another field in the DB. That way when the user logs in, you can use the salt again to test to see if the hashes match. -- Aaron Turner http://synfin.net/ http://tcpreplay.synfin.net/ - Pcap editing and replay tools for Unix & Windows They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety. -- Benjamin Franklin