From 181bc41d7a438261394a0f08c85b63895e82fe8f Mon Sep 17 00:00:00 2001 From: Andrew Pamment Date: Thu, 4 Aug 2016 21:49:51 +1000 Subject: [PATCH] Another fix for Password Hashing --- users.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/users.c b/users.c index 2631bc8..1483fe4 100644 --- a/users.c +++ b/users.c @@ -225,7 +225,8 @@ struct user_record *check_user_pass(int socket, char *loginname, char *password) sqlite3 *db; sqlite3_stmt *res; int rc; - char *sql = "SELECT * FROM users WHERE loginname LIKE ?"; + char *sql = "SELECT loginname, password, salt, firstname," + "lastname, email, location, sec_level, last_on, time_left, cur_mail_conf, cur_mail_area, cur_file_dir, cur_file_sub, times_on FROM users WHERE loginname LIKE ?"; char *pass_hash; sprintf(buffer, "%s/users.sq3", conf.bbs_path);