Bug #66835 [Opn->Nab]: password_verifiy
| From: | nikic@php.net | Date: | Thu, 06 Mar 2014 13:44:17 +0000 |
| Subject: | Bug #66835 [Opn->Nab]: password_verifiy | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-184575@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66835&edit=1
ID: 66835
Updated by: nikic@php.net
Reported by: pl dot lamballais at flashover dot fr
Summary: password_verifiy
-Status: Open
+Status: Not a bug
Type: Bug
Package: *General Issues
Operating System: Linux
PHP Version: 5.5.10
Block user comment: N
Private report: N
New Comment:
"...$BCryptRequires22Chrcte..." will interpolate the value of the variable
$BCryptRequires22Chrcte into the string. I would recommend to enable notices during development.
Previous Comments:
------------------------------------------------------------------------
[2014-03-06 13:39:21] pl dot lamballais at flashover dot fr
Description:
------------
---
From manual page: http://www.php.net/function.password-verify
---
System is:Linux webd497.20gp.ha.ovh.net 3.10.23-grsec-mutu-grs-ipv6-64+ #42 SMP Wed Feb 26 12:45:33
CET 2014 x86_64
PHP version is 5.5.7
Notice a strange comportemnt of password_verify() depending on the fact the hash variable is using
' or ".
I start to think this affect also the hash builder as I've some user records in my database
which are seen as "correct" using password_verify and others which are seen as "bad
password" when in fact they are all build the same way.
Test script:
---------------
// First exemple will give "Password is valid!"
$hash = '$2y$07$BCryptRequires22Chrcte/VlQH0piJtjXl.0t1XkA8pw9dMXTpOq';
if (password_verify('rasmuslerdorf', $hash))
{
echo 'Password is valid!';} else {
echo 'Invalid password.';}
// But this one will will give "Invalid password!"
$hash = "$2y$07$BCryptRequires22Chrcte/VlQH0piJtjXl.0t1XkA8pw9dMXTpOq";
if (password_verify('rasmuslerdorf', $hash))
{
echo 'Password is valid!';} else {
echo 'Invalid password.';}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66835&edit=1