English 中文(简体)
查询密码对查询参数或状况
原标题:Check password hash over query parameter or if condition

我要问的是,在蒙戈布省,情况最好如此:

db.users.findOne({ username :  example ,  password :  5f189664bb2e58d4e2ee879835b13a7e3a790e14 })

或者以类似情况对密码进行核对:

user = db.users.findOne({ username :  example })
if user[ password ] == passwordHash:
    print "Hello user"

感谢! Jarus

最佳回答

如果发现用户,但密码是错误的,这取决于你想要做什么。

  • If you want to display "Incorrect username or password" you can use either method.
  • If you want to display "Incorrect password" you need the second method as the first method cannot distinguish between the username being valid and the password being wrong, and the user not existing.

注:如果你想保持你的系统安全,你可能比第二种方法更喜欢第一种方法。 第二种方法采用不同的编码方法,取决于用户名称是否存在,密码是错误的,或者用户名称没有。 这可能导致泄露关于贵系统有哪些用户名称的信息,这对攻击者有用。

问题回答

暂无回答




相关问题
Can Django models use MySQL functions?

Is there a way to force Django models to pass a field to a MySQL function every time the model data is read or loaded? To clarify what I mean in SQL, I want the Django model to produce something like ...

An enterprise scheduler for python (like quartz)

I am looking for an enterprise tasks scheduler for python, like quartz is for Java. Requirements: Persistent: if the process restarts or the machine restarts, then all the jobs must stay there and ...

How to remove unique, then duplicate dictionaries in a list?

Given the following list that contains some duplicate and some unique dictionaries, what is the best method to remove unique dictionaries first, then reduce the duplicate dictionaries to single ...

What is suggested seed value to use with random.seed()?

Simple enough question: I m using python random module to generate random integers. I want to know what is the suggested value to use with the random.seed() function? Currently I am letting this ...

How can I make the PyDev editor selectively ignore errors?

I m using PyDev under Eclipse to write some Jython code. I ve got numerous instances where I need to do something like this: import com.work.project.component.client.Interface.ISubInterface as ...

How do I profile `paster serve` s startup time?

Python s paster serve app.ini is taking longer than I would like to be ready for the first request. I know how to profile requests with middleware, but how do I profile the initialization time? I ...

Pragmatically adding give-aways/freebies to an online store

Our business currently has an online store and recently we ve been offering free specials to our customers. Right now, we simply display the special and give the buyer a notice stating we will add the ...

Converting Dictionary to List? [duplicate]

I m trying to convert a Python dictionary into a Python list, in order to perform some calculations. #My dictionary dict = {} dict[ Capital ]="London" dict[ Food ]="Fish&Chips" dict[ 2012 ]="...

热门标签