check username and password in database

Collapse
This topic is closed.
X
X
 
  • Time
  • Show
Clear All
new posts
  • Kevin O'Brien

    #1

    check username and password in database

    Hello,

    I am creating a sign on screen for my application in which I want to store
    the username and password in a database table. I was thinking of putting a
    combo box connected to the database to pull up the usernames and then having
    a textbox for the user to enter their password.

    Can someone tell me please how to compare the contents of the textbox to the
    password in the database?

    Thank you,
    Kevin


  • Spam Catcher

    #2
    Re: check username and password in database

    "Kevin O'Brien" <kobrien@nshs.e duwrote in
    news:u52dgyZ4GH A.3400@TK2MSFTN GP04.phx.gbl:
    I am creating a sign on screen for my application in which I want to
    store the username and password in a database table. I was thinking
    of putting a combo box connected to the database to pull up the
    usernames and then having a textbox for the user to enter their
    password.
    Rather prompt for the username/password - then run the query:

    SELECT COUNT(1) FROM USERS WHERE UserName = @UserName AND Password =
    @Password

    Use SQLParameters to avoid injection attacks.

    Comment

    • Kevin O'Brien

      #3
      Re: check username and password in database

      Hi,

      So you are saying I should created 2 unbound textboxes to prompt for
      username and password and name the textboxes UserName and Password? Then I
      can run this SQL select statement right from my VB code?

      Sorry for the simple questions but this is my first crack at querying a
      database from VB.

      Thanks,
      Kevin




      "Spam Catcher" <spamhoneypot@r ogers.comwrote in message
      news:Xns984A9B6 3C359usenethone ypotrogers@127. 0.0.1...
      "Kevin O'Brien" <kobrien@nshs.e duwrote in
      news:u52dgyZ4GH A.3400@TK2MSFTN GP04.phx.gbl:
      >
      >I am creating a sign on screen for my application in which I want to
      >store the username and password in a database table. I was thinking
      >of putting a combo box connected to the database to pull up the
      >usernames and then having a textbox for the user to enter their
      >password.
      >
      Rather prompt for the username/password - then run the query:
      >
      SELECT COUNT(1) FROM USERS WHERE UserName = @UserName AND Password =
      @Password
      >
      Use SQLParameters to avoid injection attacks.
      >

      Comment

      • Spam Catcher

        #4
        Re: check username and password in database

        "Kevin O'Brien" <kobrien@nshs.e duwrote in
        news:Oli5KJa4GH A.3604@TK2MSFTN GP03.phx.gbl:
        So you are saying I should created 2 unbound textboxes to prompt for
        username and password and name the textboxes UserName and Password?
        Then I can run this SQL select statement right from my VB code?
        Exactly ; )


        To query the DB, you can do:

        Dim Command As New SqlClient.SqlCo mmand
        Command.Connect ion = MyConnectionObj ect
        Command.Command Text = "SELECT COUNT(1) FROM TABLE WHERE UserName =
        @UserName AND Password = @Password"

        Command.Paramet ers.Add(New SqlClient.SqlPa rameter("@UserN ame",
        txtUserName.tex t))
        Command.Paramet ers.Add(New SqlClient.SqlPa rameter("@UserN ame",
        txtPassword.tex t))

        'If count 0 means username + password matched
        If Command.Execute Scalar 0 Then
        MsgBox("Success ful Login")
        Else
        MsgBox("Try Again")
        End If

        Comment

        • Kevin O'Brien

          #5
          Re: check username and password in database

          I'll give it a shot!

          Thank you,
          Kevin


          "Spam Catcher" <spamhoneypot@r ogers.comwrote in message
          news:Xns984AAA0 C02FA8usenethon eypotrogers@127 .0.0.1...
          "Kevin O'Brien" <kobrien@nshs.e duwrote in
          news:Oli5KJa4GH A.3604@TK2MSFTN GP03.phx.gbl:
          >
          >So you are saying I should created 2 unbound textboxes to prompt for
          >username and password and name the textboxes UserName and Password?
          >Then I can run this SQL select statement right from my VB code?
          >
          Exactly ; )
          >
          >
          To query the DB, you can do:
          >
          Dim Command As New SqlClient.SqlCo mmand
          Command.Connect ion = MyConnectionObj ect
          Command.Command Text = "SELECT COUNT(1) FROM TABLE WHERE UserName =
          @UserName AND Password = @Password"
          >
          Command.Paramet ers.Add(New SqlClient.SqlPa rameter("@UserN ame",
          txtUserName.tex t))
          Command.Paramet ers.Add(New SqlClient.SqlPa rameter("@UserN ame",
          txtPassword.tex t))
          >
          'If count 0 means username + password matched
          If Command.Execute Scalar 0 Then
          MsgBox("Success ful Login")
          Else
          MsgBox("Try Again")
          End If

          Comment

          • C-Services Holland b.v.

            #6
            Re: check username and password in database

            Kevin O'Brien wrote:
            I'll give it a shot!
            >
            Thank you,
            Kevin
            >
            >
            "Spam Catcher" <spamhoneypot@r ogers.comwrote in message
            news:Xns984AAA0 C02FA8usenethon eypotrogers@127 .0.0.1...
            >
            >>"Kevin O'Brien" <kobrien@nshs.e duwrote in
            >>news:Oli5KJa4 GHA.3604@TK2MSF TNGP03.phx.gbl:
            >>
            >>
            >>>So you are saying I should created 2 unbound textboxes to prompt for
            >>>username and password and name the textboxes UserName and Password?
            >>>Then I can run this SQL select statement right from my VB code?
            >>
            >>Exactly ; )
            >>
            >>
            >>To query the DB, you can do:
            >>
            >>Dim Command As New SqlClient.SqlCo mmand
            >>Command.Conne ction = MyConnectionObj ect
            >>Command.Comma ndText = "SELECT COUNT(1) FROM TABLE WHERE UserName =
            >>@UserName AND Password = @Password"
            >>
            >>Command.Param eters.Add(New SqlClient.SqlPa rameter("@UserN ame",
            >>txtUserName.t ext))
            >>Command.Param eters.Add(New SqlClient.SqlPa rameter("@UserN ame",
            >>txtPassword.t ext))
            >>
            >>'If count 0 means username + password matched
            >>If Command.Execute Scalar 0 Then
            > MsgBox("Success ful Login")
            >>Else
            > MsgBox("Try Again")
            >>End If
            >
            >
            >
            Just a thought: Giving all registered names is not a good idea from a
            security standpoint. Just give 2 boxes (username and password) and when
            they don't match tell them there's a login error, don't tell them which
            of the 2 doesn't match. Also, don't store the password. Store the hash
            of the password.


            --
            Rinze van Huizen
            C-Services Holland b.v

            Comment

            • Miro

              #7
              Re: check username and password in database

              Izzy posted this a couple days ago.
              I havnt used it yet, but I will in about a week. - He says it works great

              You can store the Password in the access database,
              the following code will encrypt it 128 bits

              Miro
              ===== here is his post

              Here it is, I have no idea how it works, but it works great. I use it
              to encrypt passwords stored in an access file.

              To call it:

              'This will encrypt a value
              Variable = EncryptString12 8Bit(txt_Passwo rd.Text, EncryptionKey)

              'This will decrypt a value
              Variable = DecryptString12 8Bit([Password stored in DB goes here],
              EncryptionKey)

              Have fun,
              Izzy

              *************** *************** *************** *************** *************** *

              Imports System.Security .Cryptography
              Imports System.Text

              Module mod_Globals

              Public EncryptionKey As String = "justsomewordst obeusedasacrypt ionkey"

              Public Function EncryptString12 8Bit(ByVal vstrTextToBeEnc rypted As
              String, ByVal vstrEncryptionK ey As String) As String

              Dim bytValue() As Byte
              Dim bytKey() As Byte
              Dim bytEncoded() As Byte
              Dim bytIV() As Byte = {121, 241, 10, 1, 132, 74, 11, 39, 255,
              91, 45, 78, 14, 211, 22, 62}
              Dim intLength As Integer
              Dim intRemaining As Integer
              Dim objMemoryStream As New MemoryStream
              Dim objCryptoStream As CryptoStream
              Dim objRijndaelMana ged As RijndaelManaged

              vstrTextToBeEnc rypted =
              StripNullCharac ters(vstrTextTo BeEncrypted)

              bytValue =
              Encoding.ASCII. GetBytes(vstrTe xtToBeEncrypted .ToCharArray)

              intLength = Len(vstrEncrypt ionKey)

              If intLength >= 32 Then
              vstrEncryptionK ey = Strings.Left(vs trEncryptionKey , 32)
              Else
              intLength = Len(vstrEncrypt ionKey)
              intRemaining = 32 - intLength
              vstrEncryptionK ey = vstrEncryptionK ey &
              Strings.StrDup( intRemaining, "X")
              End If

              bytKey = Encoding.ASCII. GetBytes(vstrEn cryptionKey.ToC harArray)

              objRijndaelMana ged = New RijndaelManaged

              Try
              objCryptoStream = New CryptoStream(ob jMemoryStream,
              objRijndaelMana ged.CreateEncry ptor(bytKey, bytIV),
              CryptoStreamMod e.Write)
              objCryptoStream .Write(bytValue , 0, bytValue.Length )
              objCryptoStream .FlushFinalBloc k()
              bytEncoded = objMemoryStream .ToArray
              objMemoryStream .Close()
              objCryptoStream .Close()
              Catch

              End Try

              Return Convert.ToBase6 4String(bytEnco ded)

              End Function

              Public Function DecryptString12 8Bit(ByVal vstrStringToBeD ecrypted
              As String, ByVal vstrDecryptionK ey As String) As String

              Dim bytDataToBeDecr ypted() As Byte
              Dim bytTemp() As Byte
              Dim bytIV() As Byte = {121, 241, 10, 1, 132, 74, 11, 39, 255,
              91, 45, 78, 14, 211, 22, 62}
              Dim objRijndaelMana ged As New RijndaelManaged
              Dim objMemoryStream As MemoryStream
              Dim objCryptoStream As CryptoStream
              Dim bytDecryptionKe y() As Byte
              Dim intLength As Integer
              Dim intRemaining As Integer
              Dim intCtr As Integer
              Dim strReturnString As String = String.Empty
              Dim achrCharacterAr ray() As Char
              Dim intIndex As Integer

              bytDataToBeDecr ypted =
              Convert.FromBas e64String(vstrS tringToBeDecryp ted)

              intLength = Len(vstrDecrypt ionKey)

              If intLength >= 32 Then
              vstrDecryptionK ey = Strings.Left(vs trDecryptionKey , 32)
              Else
              intLength = Len(vstrDecrypt ionKey)
              intRemaining = 32 - intLength
              vstrDecryptionK ey = vstrDecryptionK ey &
              Strings.StrDup( intRemaining, "X")
              End If

              bytDecryptionKe y =
              Encoding.ASCII. GetBytes(vstrDe cryptionKey.ToC harArray)

              ReDim bytTemp(bytData ToBeDecrypted.L ength)

              objMemoryStream = New MemoryStream(by tDataToBeDecryp ted)

              Try

              objCryptoStream = New CryptoStream(ob jMemoryStream,
              objRijndaelMana ged.CreateDecry ptor(bytDecrypt ionKey, bytIV),
              CryptoStreamMod e.Read)
              objCryptoStream .Read(bytTemp, 0, bytTemp.Length)
              objCryptoStream .FlushFinalBloc k()
              objMemoryStream .Close()
              objCryptoStream .Close()

              Catch

              End Try

              Return StripNullCharac ters(Encoding.A SCII.GetString( bytTemp))

              End Function


              Public Function StripNullCharac ters(ByVal vstrStringWithN ulls As
              String) As String

              Dim intPosition As Integer
              Dim strStringWithOu tNulls As String

              intPosition = 1
              strStringWithOu tNulls = vstrStringWithN ulls

              Do While intPosition 0
              intPosition = InStr(intPositi on, vstrStringWithN ulls,
              vbNullChar)

              If intPosition 0 Then
              strStringWithOu tNulls = Left$(strString WithOutNulls,
              intPosition - 1) & _
              Right$(strStrin gWithOutNulls,
              Len(strStringWi thOutNulls) - intPosition)
              End If

              If intPosition strStringWithOu tNulls.Length Then
              Exit Do
              End If
              Loop

              Return strStringWithOu tNulls

              End Function

              End Module

              *************** *************** *************** *************** *************** *************
              =============== ===

              "C-Services Holland b.v." <csh@DELTHIScsh 4.nlwrote in message
              news:2YmdnSaQI_ dgzIfYRVnygA@ze elandnet.nl...
              Kevin O'Brien wrote:
              >I'll give it a shot!
              >>
              >Thank you,
              >Kevin
              >>
              >>
              >"Spam Catcher" <spamhoneypot@r ogers.comwrote in message
              >news:Xns984AAA 0C02FA8usenetho neypotrogers@12 7.0.0.1...
              >>
              >>>"Kevin O'Brien" <kobrien@nshs.e duwrote in
              >>>news:Oli5KJa 4GHA.3604@TK2MS FTNGP03.phx.gbl :
              >>>
              >>>
              >>>>So you are saying I should created 2 unbound textboxes to prompt for
              >>>>username and password and name the textboxes UserName and Password?
              >>>>Then I can run this SQL select statement right from my VB code?
              >>>
              >>>Exactly ; )
              >>>
              >>>
              >>>To query the DB, you can do:
              >>>
              >>>Dim Command As New SqlClient.SqlCo mmand
              >>>Command.Conn ection = MyConnectionObj ect
              >>>Command.Comm andText = "SELECT COUNT(1) FROM TABLE WHERE UserName =
              >>>@UserName AND Password = @Password"
              >>>
              >>>Command.Para meters.Add(New SqlClient.SqlPa rameter("@UserN ame",
              >>>txtUserName. text))
              >>>Command.Para meters.Add(New SqlClient.SqlPa rameter("@UserN ame",
              >>>txtPassword. text))
              >>>
              >>>'If count 0 means username + password matched
              >>>If Command.Execute Scalar 0 Then
              >> MsgBox("Success ful Login")
              >>>Else
              >> MsgBox("Try Again")
              >>>End If
              >>
              >>
              >>
              >
              Just a thought: Giving all registered names is not a good idea from a
              security standpoint. Just give 2 boxes (username and password) and when
              they don't match tell them there's a login error, don't tell them which of
              the 2 doesn't match. Also, don't store the password. Store the hash of the
              password.
              >
              >
              --
              Rinze van Huizen
              C-Services Holland b.v

              Comment

              • Kevin O'Brien

                #8
                Re: check username and password in database

                Hey,

                I created a new form with two textboxes - txtUserName and txtPassword - and
                a command button.
                I have a database called signon.mdf with a table called users.

                When I pasted this code in the buttom click event I have two errors:
                Command.Connect ion = MyConnectionObj ect - MyConnectionObj ect is not
                declared.
                And on the @ symbol on the select statement.

                Can you please tell me what I am going wrong?

                thank you!!
                Kevin



                "Spam Catcher" <spamhoneypot@r ogers.comwrote in message
                news:Xns984AAA0 C02FA8usenethon eypotrogers@127 .0.0.1...
                "Kevin O'Brien" <kobrien@nshs.e duwrote in
                news:Oli5KJa4GH A.3604@TK2MSFTN GP03.phx.gbl:
                >
                >So you are saying I should created 2 unbound textboxes to prompt for
                >username and password and name the textboxes UserName and Password?
                >Then I can run this SQL select statement right from my VB code?
                >
                Exactly ; )
                >
                >
                To query the DB, you can do:
                >
                Dim Command As New SqlClient.SqlCo mmand
                Command.Connect ion = MyConnectionObj ect
                Command.Command Text = "SELECT COUNT(1) FROM TABLE WHERE UserName =
                @UserName AND Password = @Password"
                >
                Command.Paramet ers.Add(New SqlClient.SqlPa rameter("@UserN ame",
                txtUserName.tex t))
                Command.Paramet ers.Add(New SqlClient.SqlPa rameter("@UserN ame",
                txtPassword.tex t))
                >
                'If count 0 means username + password matched
                If Command.Execute Scalar 0 Then
                MsgBox("Success ful Login")
                Else
                MsgBox("Try Again")
                End If

                Comment

                • Jim Wooley

                  #9
                  Re: check username and password in database

                  Typically with passwords, you don't need to be able to decrypt it, thus a
                  one way hash can be sufficient. Just compare the hashes rather than the plain
                  text values. Give your users a mechanism to have their password reset and
                  email them the new password to the email they registered when they created
                  the account if they forget it.

                  Here's some quick code (based on the security snippet) to hash a password
                  Public Function HashPassword(pa ssword As String) as string
                  Dim sha1CryptoServi ce As SHA1CryptoServi ceProvider = New SHA1CryptoServi ceProvider()
                  Dim byteValue() As Byte = Encoding.UTF8.G etBytes(passwor d)
                  Dim hashValue() As Byte = sha1CryptoServi ce.ComputeHash( byteValue)
                  return System.Text.Enc oding.UTF8.GetS tring(hashValue )
                  End Function

                  Note, you can easily substitute the MD5 for SHA1 if you want.
                  Jim Wooley



                  Comment

                  • Kevin O'Brien

                    #10
                    Re: check username and password in database

                    Hey,

                    I have the errors worked out except for:
                    Command.Connect ion = MyConnectionObj ect

                    I get the error:

                    'MyConnectionOb ject' is not declared.



                    I tried putting in the name of the data set in place of Myconnectionobj ect
                    but that didn't work either. any help would be greatly appreciated!

                    Thanks,

                    Kevin





                    "Spam Catcher" <spamhoneypot@r ogers.comwrote in message
                    news:Xns984AAA0 C02FA8usenethon eypotrogers@127 .0.0.1...
                    "Kevin O'Brien" <kobrien@nshs.e duwrote in
                    news:Oli5KJa4GH A.3604@TK2MSFTN GP03.phx.gbl:
                    >
                    >So you are saying I should created 2 unbound textboxes to prompt for
                    >username and password and name the textboxes UserName and Password?
                    >Then I can run this SQL select statement right from my VB code?
                    >
                    Exactly ; )
                    >
                    >
                    To query the DB, you can do:
                    >
                    Dim Command As New SqlClient.SqlCo mmand
                    Command.Connect ion = MyConnectionObj ect
                    Command.Command Text = "SELECT COUNT(1) FROM TABLE WHERE UserName =
                    @UserName AND Password = @Password"
                    >
                    Command.Paramet ers.Add(New SqlClient.SqlPa rameter("@UserN ame",
                    txtUserName.tex t))
                    Command.Paramet ers.Add(New SqlClient.SqlPa rameter("@UserN ame",
                    txtPassword.tex t))
                    >
                    'If count 0 means username + password matched
                    If Command.Execute Scalar 0 Then
                    MsgBox("Success ful Login")
                    Else
                    MsgBox("Try Again")
                    End If

                    Comment

                    • Spam Catcher

                      #11
                      Re: check username and password in database

                      "Kevin O'Brien" <kobrien@nshs.e duwrote in
                      news:ORXg1ci5GH A.4996@TK2MSFTN GP04.phx.gbl:
                      I have the errors worked out except for:
                      Command.Connect ion = MyConnectionObj ect
                      >
                      I get the error:
                      >
                      'MyConnectionOb ject' is not declared.
                      >
                      >
                      >
                      I tried putting in the name of the data set in place of
                      Myconnectionobj ect but that didn't work either. any help would be
                      greatly appreciated!
                      You need to declare a connection object...

                      i.e.:

                      Dim _Connection as New SQLClient.Conne ction

                      Then:

                      Command.Connect ion = _Connection

                      I see that you're not familiar with ADO.NET at all - take some time and
                      Google some ADO.NET tutorials and you'll find things will go a lot
                      smoother.

                      Comment

                      • Kevin O'Brien

                        #12
                        Re: check username and password in database

                        Point taken.

                        Thank you for your help.

                        Kevin


                        "Spam Catcher" <spamhoneypot@r ogers.comwrote in message
                        news:Xns985073F 25C9AEusenethon eypotrogers@127 .0.0.1...
                        "Kevin O'Brien" <kobrien@nshs.e duwrote in
                        news:ORXg1ci5GH A.4996@TK2MSFTN GP04.phx.gbl:
                        >
                        >I have the errors worked out except for:
                        >Command.Connec tion = MyConnectionObj ect
                        >>
                        >I get the error:
                        >>
                        >'MyConnectionO bject' is not declared.
                        >>
                        >>
                        >>
                        >I tried putting in the name of the data set in place of
                        >Myconnectionob ject but that didn't work either. any help would be
                        >greatly appreciated!
                        >
                        You need to declare a connection object...
                        >
                        i.e.:
                        >
                        Dim _Connection as New SQLClient.Conne ction
                        >
                        Then:
                        >
                        Command.Connect ion = _Connection
                        >
                        I see that you're not familiar with ADO.NET at all - take some time and
                        Google some ADO.NET tutorials and you'll find things will go a lot
                        smoother.

                        Comment

                        Working...