Bug #66874 [Opn->Nab]: Hashing gives same output for a specific string

From: Date: Mon, 10 Mar 2014 02:02:43 +0000
Subject: Bug #66874 [Opn->Nab]: Hashing gives same output for a specific string
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-184673@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66874&edit=1 ID: 66874 Updated by: requinix@php.net Reported by: amish dot mhatre dot 1993 at gmail dot com Summary: Hashing gives same output for a specific string -Status: Open +Status: Not a bug Type: Bug Package: hash related Operating System: Windows 7 PHP Version: 5.4.26 Block user comment: N Private report: N New Comment: Thank you for taking the time to write to us, but this is not a bug. Please double-check the documentation available at http://www.php.net/manual/ and the instructions on how to report a bug at http://bugs.php.net/how-to-report.php Your salt is triggering CRYPT_STD_DES, and as stated in the documentation: > The standard DES-based crypt() returns the salt as the first two characters of > the output. It also only uses the first eight characters of str, so longer > strings that start with the same eight characters will generate the same result > (when the same salt is used). Previous Comments: ------------------------------------------------------------------------ [2014-03-10 01:53:00] amish dot mhatre dot 1993 at gmail dot com Description: ------------ --- From manual page: http://www.php.net/function.crypt --- Test script: --------------- <?php echo "Using Salt: tRySalTIng@free "; echo "<br><br>"; $pwd="1234567890"; $ped=crypt($pwd,'tRySalTIng@free'); echo "1234567890: ".$ped."<br><br>"; $pwd="123456789123"; $ped=crypt($pwd,'tRySalTIng@free'); echo "123456789123: ".$ped."\n"; echo "<br><br>"; echo "<br><br>"; echo "Using Salt: BLA&ZE11005!@98 "; echo "<br><br>"; $pwd="1234567890"; $ped=crypt($pwd,'BLA&ZE11005!@98'); echo "1234567890: ".$ped."<br><br>"; $pwd="123456789123"; $ped=crypt($pwd,'BLA&ZE11005!@98'); echo "123456789123: ".$ped."\n"; ?> Expected result: ---------------- Got following output: Using Salt: tRySalTIng@free 1234567890: tRIrkXjwVoQ4E 123456789123: tRIrkXjwVoQ4E Using Salt: BLA&ZE11005!@98 1234567890: BLBaYGP/QWoPM 123456789123: BLBaYGP/QWoPM Both gave same hashed values for above strings. Well try to checkout this bug asap because it is not at all safe regarding security point of view. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66874&edit=1

« previous php.bugs (#184673) next »