I am currently making a password manager, therefore I make a log-in form with username and password fields. I want to bcrypt the password. I store the salt and the hashed password in the database (screenshot 1). When the user enters their username and password what I do is:
1.Retrieve the salt from the DB and use the BCrypt.Net.BCrypt.HashPassword(password.Text, sal) method to hash the submitted password with the salt from the database
2.Retrieve the original hashed password from the db table, and then use the method BCrypt.Net.BCrypt.Verify(submhash, passdb) to check if the 2 passwords hashes match.
3.If they do match I open the main form of the program.
However the VS Studio throws an exception : Invalid salt version ( screenshot 2)
I would like to ask where is the problem and how can I fix it?
conn.Open();
MySqlCommand cmd = new MySqlCommand();
cmd.Connection = conn;
cmd.Parameters.AddWithValue("@usr", username.Text);
// cmd.Parameters.AddWithValue("@pas", password.Text);
cmd.CommandText = "select password from users where username = @usr";
passdb = (string)cmd.ExecuteScalar();
MySqlCommand ss = new MySqlCommand();
ss.Connection = conn;
ss.Parameters.AddWithValue("@uun", username.Text);
ss.CommandText = "select salt from users where username = @uun";
sal= (string)ss.ExecuteScalar();
submhash = BCrypt.Net.BCrypt.HashPassword(password.Text, sal);
MySqlCommand com = new MySqlCommand();
com.Connection = conn;
com.Parameters.AddWithValue("@unm", username.Text);
if (BCrypt.Net.BCrypt.Verify(submhash, passdb))
{
frmMain fm = new frmMain();
SesUser.username = username.Text;
SesUser.password = password.Text;
this.Hide();
fm.Show();
}
else
{
MessageBox.Show("Username or password is incorrect!","Error",MessageBoxButtons.OK,MessageBoxIcon.Error);
i++;
}
}