English 中文(简体)
我如何打上我用户桌上的行政密码?
原标题:How do I hash the admin password in my Users table?

我如何打上我用户桌上的行政密码?

Using SQL Server 2008 R2

我知道存在一种加密指挥系统,但我不敢肯定,如果能够使用一种电梯。

Example: Table called users, with entry of admin, password is sha1( password )

最佳回答

Use HASHBYTES and specify SHA1 as the algorithm. Example:

SELECT HASHBYTES( SHA1 , @password);

Edit:,正如西瓦在评论中所说的那样,你实际上应当对你的密码进行不同和至少加盐。

See here: Preferred Method of Storing Passwords In Database

问题回答

请注意,上述任何内容都不是储存密码的斜体。 利用PBKDF2(PKCS #5, RFC2898),多次张贴salted><>>> /em>密码(OWASP建议2012年为64 000倍,每2年翻一番)。 理想的情况是,它储存着随机的每个用户盐,但时间不一。

Even better, bounce the proposed password against a list of known bad passwords, ideally with basic cracking rules already applied (1337 speak translation), so "P@$$w0rd" isn t allowed.

See the OWASP Password Storage Cheat Sheet: https://www.owasp.org/index.php?title=Password_Storage_Cheat_Sheet&setlang=es

加密和洗衣之间存在差异。 加密翻译通常使用电离层的便衣物,可以向原始投入逆转,但不能向原始投入逆转。

您请您使用<代码>。 HLMBYTES功能:

DECLARE @YourInput nvarchar(4000);
SELECT @YourInput = CONVERT(nvarchar(4000), dslfdkjLK85kldhnv$n000#knf );
SELECT HASHBYTES( SHA1 , @YourInput);

如果你重新使用服务器2012年,你可以使用:

SELECT HASHBYTES( SHA_256 , @YourInput); // SHA 256 or SHA_512





相关问题
SQL SubQuery getting particular column

I noticed that there were some threads with similar questions, and I did look through them but did not really get a convincing answer. Here s my question: The subquery below returns a Table with 3 ...

难以执行 REGEXP_SUBSTR

I m 查询Oracle 10g。 我有两张表格(样本数据见下文)。 i m 试图提取一些领域

SQL Query Shortcuts

What are some cool SQL shorthands that you know of? For example, something I learned today is you can specify to group by an index: SELECT col1, col2 FROM table GROUP BY 2 This will group by col2

PHP array callback functions for cleaning output

I have an array of output from a database. I am wondering what the cleanest way to filter the values is example array Array ( [0] => Array ( [title] => title 1 ...

OracleParameter and DBNull.Value

we have a table in an Oracle Database which contains a column with the type Char(3 Byte). Now we use a parameterized sql to select some rows with a DBNull.Value and it doesn t work: OracleCommand ...

Running numbers in SQL

I have a SQL-statement like this: SELECT name FROM users WHERE deleted = 0; How can i create a result set with a running number in the first row? So the result would look like this: 1 Name_1 2 ...

How to get SQL queries for each user where env is production

I’m developing an application dedicated to generate statistical reports, I would like that user after saving their stat report they save sql queries too. To do that I wrote the following module: ...

热门标签