Bug #66874 [Nab]: Hashing gives same output for a specific string

From: Date: Mon, 10 Mar 2014 02:10:36 +0000
Subject: Bug #66874 [Nab]: Hashing gives same output for a specific string
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-184674@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66874&edit=1 ID: 66874 Updated by: requinix@php.net Reported by: amish dot mhatre dot 1993 at gmail dot com Summary: Hashing gives same output for a specific string Status: Not a bug Type: Bug Package: hash related Operating System: Windows 7 PHP Version: 5.4.26 Block user comment: N Private report: N New Comment: And while I'm here, Don't try to do your own password hashing. Unless you're an expert in cryptography you will get something wrong, such as not use crypt() or the salts available to it correctly. Use http://www.php.net/manual/en/book.password.php in PHP 5.5+ or https://github.com/ircmaxell/password_compat for earlier versions. Previous Comments: ------------------------------------------------------------------------ [2014-03-10 02:02:43] requinix@php.net Thank you for taking the time to write to us, but this is not a bug. Please double-check the documentation available at http://www.php.net/manual/ and the instructions on how to report a bug at http://bugs.php.net/how-to-report.php Your salt is triggering CRYPT_STD_DES, and as stated in the documentation: > The standard DES-based crypt() returns the salt as the first two characters of > the output. It also only uses the first eight characters of str, so longer > strings that start with the same eight characters will generate the same result > (when the same salt is used). ------------------------------------------------------------------------ [2014-03-10 01:53:00] amish dot mhatre dot 1993 at gmail dot com Description: ------------ --- From manual page: http://www.php.net/function.crypt --- Test script: --------------- <?php echo "Using Salt: tRySalTIng@free "; echo "<br><br>"; $pwd="1234567890"; $ped=crypt($pwd,'tRySalTIng@free'); echo "1234567890: ".$ped."<br><br>"; $pwd="123456789123"; $ped=crypt($pwd,'tRySalTIng@free'); echo "123456789123: ".$ped."\n"; echo "<br><br>"; echo "<br><br>"; echo "Using Salt: BLA&ZE11005!@98 "; echo "<br><br>"; $pwd="1234567890"; $ped=crypt($pwd,'BLA&ZE11005!@98'); echo "1234567890: ".$ped."<br><br>"; $pwd="123456789123"; $ped=crypt($pwd,'BLA&ZE11005!@98'); echo "123456789123: ".$ped."\n"; ?> Expected result: ---------------- Got following output: Using Salt: tRySalTIng@free 1234567890: tRIrkXjwVoQ4E 123456789123: tRIrkXjwVoQ4E Using Salt: BLA&ZE11005!@98 1234567890: BLBaYGP/QWoPM 123456789123: BLBaYGP/QWoPM Both gave same hashed values for above strings. Well try to checkout this bug asap because it is not at all safe regarding security point of view. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66874&edit=1

« previous php.bugs (#184674) next »