From c614f1b47ddf62d166a61f51bc5c9ff196925616 Mon Sep 17 00:00:00 2001 From: tbrehm <t.brehm@ispconfig.org> Date: Mon, 12 Sep 2011 04:45:22 -0400 Subject: [PATCH] Fixed: FS#1741 - Password after update --- interface/web/login/password_reset.php | 11 ++--------- 1 files changed, 2 insertions(+), 9 deletions(-) diff --git a/interface/web/login/password_reset.php b/interface/web/login/password_reset.php index 5c23cc4..659859a 100644 --- a/interface/web/login/password_reset.php +++ b/interface/web/login/password_reset.php @@ -52,15 +52,8 @@ $client = $app->db->queryOneRecord("SELECT * FROM client WHERE username = '$username' AND email = '$email'"); if($client['client_id'] > 0) { - $new_password = md5 (uniqid (rand())); - $salt="$1$"; - $base64_alphabet='ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/'; - for ($n=0;$n<8;$n++) { - //$salt.=chr(mt_rand(64,126)); - $salt.=$base64_alphabet[mt_rand(0,63)]; - } - $salt.="$"; - $new_password_encrypted = crypt($new_password,$salt); + $new_password = $app->auth->get_random_password(); + $new_password_encrypted = $app->auth->crypt_password($new_password); $new_password_encrypted = $app->db->quote($new_password_encrypted); $username = $app->db->quote($client['username']); -- Gitblit v1.9.1