Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - Bug in Member API code
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Bug in Member API code

 Post Reply Post Reply
Author
adamwsh View Drop Down
Newbie
Newbie


Joined: 28 December 2007
Status: Offline
Points: 14
Post Options Post Options   Thanks (0) Thanks(0)   Quote adamwsh Quote  Post ReplyReply Direct Link To This Post Topic: Bug in Member API code
    Posted: 11 August 2011 at 3:25pm

On or around line 247 of functions_member_API.asp, in the section with the
comment: 'If the password doest match that on record we need to create a new
password to save to db

the line:
strPassword = HashEncode(*strPassword *& strSalt)

should be:
strPassword = HashEncode(*LCase(Trim(Session("PASSWORD")))* & strSalt)

The incorrect line is Hashing an already hashed password.

However, I also found out, if the password being passed to this call is already hashed by the calling system, it will never stay in sync. This isn't really a problem expect for an Admin. If an admin tries to log into the admin area, their entered password will never match what is stored in the WW DB.  I'm not sure why you bother having the admin log in a 2nd time. They've already logged into the system once.  Eliminating the 2nd login will eliminate this issue.

Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 12 August 2011 at 8:23pm
Thank you will look in to this.
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.