Bug #66874 [Opn->Nab]: Hashing gives same output for a specific string
| From: | requinix@php.net | Date: | Mon, 10 Mar 2014 02:02:43 +0000 |
| Subject: | Bug #66874 [Opn->Nab]: Hashing gives same output for a specific string | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-184673@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66874&edit=1
ID: 66874
Updated by: requinix@php.net
Reported by: amish dot mhatre dot 1993 at gmail dot com
Summary: Hashing gives same output for a specific string
-Status: Open
+Status: Not a bug
Type: Bug
Package: hash related
Operating System: Windows 7
PHP Version: 5.4.26
Block user comment: N
Private report: N
New Comment:
Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php
Your salt is triggering CRYPT_STD_DES, and as stated in the documentation:
> The standard DES-based crypt() returns the salt as the first two characters of
> the output. It also only uses the first eight characters of str, so longer
> strings that start with the same eight characters will generate the same result
> (when the same salt is used).
Previous Comments:
------------------------------------------------------------------------
[2014-03-10 01:53:00] amish dot mhatre dot 1993 at gmail dot com
Description:
------------
---
From manual page: http://www.php.net/function.crypt
---
Test script:
---------------
<?php
echo "Using Salt: tRySalTIng@free ";
echo "<br><br>";
$pwd="1234567890";
$ped=crypt($pwd,'tRySalTIng@free');
echo "1234567890: ".$ped."<br><br>";
$pwd="123456789123";
$ped=crypt($pwd,'tRySalTIng@free');
echo "123456789123: ".$ped."\n";
echo "<br><br>";
echo "<br><br>";
echo "Using Salt: BLA&ZE11005!@98 ";
echo "<br><br>";
$pwd="1234567890";
$ped=crypt($pwd,'BLA&ZE11005!@98');
echo "1234567890: ".$ped."<br><br>";
$pwd="123456789123";
$ped=crypt($pwd,'BLA&ZE11005!@98');
echo "123456789123: ".$ped."\n";
?>
Expected result:
----------------
Got following output:
Using Salt: tRySalTIng@free
1234567890: tRIrkXjwVoQ4E
123456789123: tRIrkXjwVoQ4E
Using Salt: BLA&ZE11005!@98
1234567890: BLBaYGP/QWoPM
123456789123: BLBaYGP/QWoPM
Both gave same hashed values for above strings. Well try to checkout this bug asap because it is not
at all safe regarding security point of view.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66874&edit=1