Bug #18267: mcrypt-blowfish data encrypted on one machine not decryptable on other machine
| From: | mcrypt at michael dot mailshell dot com | Date: | Wed, 10 Jul 2002 22:56:37 +0000 |
| Subject: | Bug #18267: mcrypt-blowfish data encrypted on one machine not decryptable on other machine | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-13773@lists.php.net to get a copy of this message | ||
From: mcrypt@michael.mailshell.com
Operating system: Linux Mandrake
PHP version: 4.2.0
PHP Bug Type: mcrypt related
Bug description: mcrypt-blowfish data encrypted on one machine not decryptable on other machine
I am able to encrypt and decrypt on each machine, but the encrypted data
can only be decrypted on that
machine. I'm guessing this is an issue with the version of mcrypt. This is
very disterbing as I have
thousands of encrypted emails of customers. As I have no key to them I
will never be able to upgrade mcrypt
w/o this bug being resolved.
Machine 1:
kernel-2.2.17-21mdk
php version: 4.2.0
# rpm -qa | grep mcrypt
libmcrypt-2.4.4-1
libmcrypt-devel-2.4.18-2
Machine 2:
kernel-2.4.18.1mdk-1-1mdk
# rpm -qa | grep mcrypt
libmcrypt4-2.5.1-1mdk
libmcrypt4-devel-2.5.1-1mdk
php-mcrypt-4.2.1-4mdk
encrypt.php:
<?
$file = './test.txt';
$fp = fopen($file, "r");
$buf = fread($fp, filesize($file));
fclose($fp);
## echo $buf;
$tmp = '123456789012345678901234';
$buf = blowfish_encrypt($buf, $tmp);
echo "md5 on encrypted data: " . md5($buf) . "\n";
$fp = fopen($file . "_enc", "w");
fwrite ($fp, $buf);
fclose($fp);
function blowfish_encrypt($data, $pass) {
if (strlen($pass) > 24) $pass = substr($pass, 0 , 24);
if (strlen($pass) < 24) $pass = str_pad($pass, 24, 'this is a very
secret pad');
$td = mcrypt_module_open (MCRYPT_BLOWFISH, "", MCRYPT_MODE_ECB, "");
$iv = mcrypt_create_iv (mcrypt_enc_get_iv_size ($td), MCRYPT_RAND);
mcrypt_generic_init ($td, $pass, $iv);
$out = mcrypt_generic ($td, $data);
mcrypt_generic_end ($td);
return $out;
}
?>
decrypt.php:
<?
$file = './test.txt_enc';
$fp = fopen($file, "r");
$buf = fread($fp, filesize($file));
fclose($fp);
echo "md5 on encrypted data: " . md5($buf) . "\n";
$pass = '123456789012345678901234';
$buf = blowfish_decrypt($buf, $pass);
echo $buf . "\n";
function blowfish_decrypt($data, $pass) {
if (strlen($pass) > 24) $pass = substr($pass, 0 , 24);
if (strlen($pass) < 24) $pass = str_pad($pass, 24, 'this is a very
secret pad');
$td = mcrypt_module_open (MCRYPT_BLOWFISH, "", MCRYPT_MODE_ECB, "");
$iv = mcrypt_create_iv (mcrypt_enc_get_iv_size ($td), MCRYPT_RAND);
mcrypt_generic_init ($td, $pass, $iv);
$out = mdecrypt_generic ($td, $data);
mcrypt_generic_end ($td);
## remove trailing 0 chars that blowfish adds
return preg_replace('/\0*$/', '', $out);
}
?>
test.txt can be anothing, I used:
"## Created: 2002-07-10 14:46:21\n"
machine 1:
# php -q encrypt.php
md5 on encrypted data: 513f9ac2b549be9a8f54aec53f899545
# php -q decrypt.php
md5 on encrypted data: 513f9ac2b549be9a8f54aec53f899545
## Created: 2002-07-10 14:46:21
#
machine 2:
# php -q encrypt.php
md5 on encrypted data: 1f4f2599844f29ef765583838cf6e553
# php -q decrypt.php
md5 on encrypted data: 1f4f2599844f29ef765583838cf6e553
## Created: 2002-07-10 14:46:21
#
[copied machine 1 test.txt_enc to this machine]
# php -q decrypt.php
md5 on encrypted data: 513f9ac2b549be9a8f54aec53f899545
DHdø?ôPXªË5ÈDð
#
--
Edit bug report at http://bugs.php.net/?id=18267&edit=1
--
Fixed in CVS: http://bugs.php.net/fix.php?id=18267&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=18267&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=18267&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=18267&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=18267&r=support
Expected behavior: http://bugs.php.net/fix.php?id=18267&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=18267&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=18267&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=18267&r=globals