Bug #18267: mcrypt-blowfish data encrypted on one machine not decryptable on other machine

From: Date: Wed, 10 Jul 2002 22:56:37 +0000
Subject: Bug #18267: mcrypt-blowfish data encrypted on one machine not decryptable on other machine
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-13773@lists.php.net to get a copy of this message
From: mcrypt@michael.mailshell.com Operating system: Linux Mandrake PHP version: 4.2.0 PHP Bug Type: mcrypt related Bug description: mcrypt-blowfish data encrypted on one machine not decryptable on other machine I am able to encrypt and decrypt on each machine, but the encrypted data can only be decrypted on that machine. I'm guessing this is an issue with the version of mcrypt. This is very disterbing as I have thousands of encrypted emails of customers. As I have no key to them I will never be able to upgrade mcrypt w/o this bug being resolved. Machine 1: kernel-2.2.17-21mdk php version: 4.2.0 # rpm -qa | grep mcrypt libmcrypt-2.4.4-1 libmcrypt-devel-2.4.18-2 Machine 2: kernel-2.4.18.1mdk-1-1mdk # rpm -qa | grep mcrypt libmcrypt4-2.5.1-1mdk libmcrypt4-devel-2.5.1-1mdk php-mcrypt-4.2.1-4mdk encrypt.php: <? $file = './test.txt'; $fp = fopen($file, "r"); $buf = fread($fp, filesize($file)); fclose($fp); ## echo $buf; $tmp = '123456789012345678901234'; $buf = blowfish_encrypt($buf, $tmp); echo "md5 on encrypted data: " . md5($buf) . "\n"; $fp = fopen($file . "_enc", "w"); fwrite ($fp, $buf); fclose($fp); function blowfish_encrypt($data, $pass) { if (strlen($pass) > 24) $pass = substr($pass, 0 , 24); if (strlen($pass) < 24) $pass = str_pad($pass, 24, 'this is a very secret pad'); $td = mcrypt_module_open (MCRYPT_BLOWFISH, "", MCRYPT_MODE_ECB, ""); $iv = mcrypt_create_iv (mcrypt_enc_get_iv_size ($td), MCRYPT_RAND); mcrypt_generic_init ($td, $pass, $iv); $out = mcrypt_generic ($td, $data); mcrypt_generic_end ($td); return $out; } ?> decrypt.php: <? $file = './test.txt_enc'; $fp = fopen($file, "r"); $buf = fread($fp, filesize($file)); fclose($fp); echo "md5 on encrypted data: " . md5($buf) . "\n"; $pass = '123456789012345678901234'; $buf = blowfish_decrypt($buf, $pass); echo $buf . "\n"; function blowfish_decrypt($data, $pass) { if (strlen($pass) > 24) $pass = substr($pass, 0 , 24); if (strlen($pass) < 24) $pass = str_pad($pass, 24, 'this is a very secret pad'); $td = mcrypt_module_open (MCRYPT_BLOWFISH, "", MCRYPT_MODE_ECB, ""); $iv = mcrypt_create_iv (mcrypt_enc_get_iv_size ($td), MCRYPT_RAND); mcrypt_generic_init ($td, $pass, $iv); $out = mdecrypt_generic ($td, $data); mcrypt_generic_end ($td); ## remove trailing 0 chars that blowfish adds return preg_replace('/\0*$/', '', $out); } ?> test.txt can be anothing, I used: "## Created: 2002-07-10 14:46:21\n" machine 1: # php -q encrypt.php md5 on encrypted data: 513f9ac2b549be9a8f54aec53f899545 # php -q decrypt.php md5 on encrypted data: 513f9ac2b549be9a8f54aec53f899545 ## Created: 2002-07-10 14:46:21 # machine 2: # php -q encrypt.php md5 on encrypted data: 1f4f2599844f29ef765583838cf6e553 # php -q decrypt.php md5 on encrypted data: 1f4f2599844f29ef765583838cf6e553 ## Created: 2002-07-10 14:46:21 # [copied machine 1 test.txt_enc to this machine] # php -q decrypt.php md5 on encrypted data: 513f9ac2b549be9a8f54aec53f899545 ”DHdø?ôPXªž‹Ë5ÈDð # -- Edit bug report at http://bugs.php.net/?id=18267&edit=1 -- Fixed in CVS: http://bugs.php.net/fix.php?id=18267&r=fixedcvs Fixed in release: http://bugs.php.net/fix.php?id=18267&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=18267&r=needtrace Try newer version: http://bugs.php.net/fix.php?id=18267&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=18267&r=support Expected behavior: http://bugs.php.net/fix.php?id=18267&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=18267&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=18267&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=18267&r=globals

« previous php.bugs (#13773) next »