Bug #66835 [Nab]: password_verifiy
| From: | pl dot lamballais at flashover dot fr | Date: | Thu, 06 Mar 2014 14:29:37 +0000 |
| Subject: | Bug #66835 [Nab]: password_verifiy | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-184580@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66835&edit=1
ID: 66835
User updated by: pl dot lamballais at flashover dot fr
Reported by: pl dot lamballais at flashover dot fr
Summary: password_verifiy
Status: Not a bug
Type: Bug
Package: *General Issues
Operating System: Linux
PHP Version: 5.5.10
Block user comment: N
Private report: N
New Comment:
Agree with nikic, not really a bug.
Maybe a good thing will be to add a note about that on the doc. Because I notice that, depending on
the hash, some are working with ' or "" and others not... :/
This means you can do your dev, test and if, unfortunatly the hash used for test are good even with
' or " you'll have some problems... later.
Previous Comments:
------------------------------------------------------------------------
[2014-03-06 13:44:17] nikic@php.net
"...$BCryptRequires22Chrcte..." will interpolate the value of the variable
$BCryptRequires22Chrcte into the string. I would recommend to enable notices during development.
------------------------------------------------------------------------
[2014-03-06 13:39:21] pl dot lamballais at flashover dot fr
Description:
------------
---
From manual page: http://www.php.net/function.password-verify
---
System is:Linux webd497.20gp.ha.ovh.net 3.10.23-grsec-mutu-grs-ipv6-64+ #42 SMP Wed Feb 26 12:45:33
CET 2014 x86_64
PHP version is 5.5.7
Notice a strange comportemnt of password_verify() depending on the fact the hash variable is using
' or ".
I start to think this affect also the hash builder as I've some user records in my database
which are seen as "correct" using password_verify and others which are seen as "bad
password" when in fact they are all build the same way.
Test script:
---------------
// First exemple will give "Password is valid!"
$hash = '$2y$07$BCryptRequires22Chrcte/VlQH0piJtjXl.0t1XkA8pw9dMXTpOq';
if (password_verify('rasmuslerdorf', $hash))
{
echo 'Password is valid!';} else {
echo 'Invalid password.';}
// But this one will will give "Invalid password!"
$hash = "$2y$07$BCryptRequires22Chrcte/VlQH0piJtjXl.0t1XkA8pw9dMXTpOq";
if (password_verify('rasmuslerdorf', $hash))
{
echo 'Password is valid!';} else {
echo 'Invalid password.';}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66835&edit=1