How to secure database passwords in PHP?
Most of the websites are providing sing up and login facility to the user. User has to create a password and use it for login to the website. But it is very important to secure the password of the user. password_hash() function provides the facility to securely store the password of the user to the database.
Syntax
password_hash(Password, PASSWORD_DEFAULT)
Example: First parameter Password will contain the normal password. The second Parameter will contain PASSWORD_BCRYPT to make secure otherwise it contains PASSWORD_DEFAULT as default. Let’s see the example to understand properly.
- dbconn.php
<?php$db_host="localhost";$db_name="secure_pass";$db_pass="";$db_user="root";$conn= mysqli_connect($db_host,$db_user,$db_pass,$db_name);if(!$conn){die('Failed to connect with server');}?>chevron_rightfilter_none - Signup Form:
<formaction="index.php"method="POST"><labelfor="username">Username</label><inputtype="text"name="username"required><br><br><labelfor="password">Password</label><inputtype="password"name="password"required><br><br><inputtype="submit"name="submit"value="submit"></form>chevron_rightfilter_none - index.php
<?php//Include database connection fileinclude'dbconn.php';if(isset($_POST['submit'])){$username=$_POST['username'];// Normal Password$pass=$_POST['password'];// Securing password using password_hash$secure_pass= password_hash($pass, PASSWORD_BCRYPT);$sql= "INSERT INTO login_tb (u_username, u_password)VALUES('$username','$secure_pass')";$result= mysqli_query($conn,$sql);}// Include HTML sign up forminclude'signup_form.php';?>chevron_rightfilter_none - Outout:Password In Database.


