Bug #67286 [Opn->Wfx]: Warning: mcrypt_encrypt(): Only keys of size 24 supported

From: Date: Thu, 15 May 2014 21:13:53 +0000
Subject: Bug #67286 [Opn->Wfx]: Warning: mcrypt_encrypt(): Only keys of size 24 supported
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-185835@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67286&edit=1 ID: 67286 Updated by: nikic@php.net Reported by: mengxiangbaidu at qq dot com Summary: Warning: mcrypt_encrypt(): Only keys of size 24 supported -Status: Open +Status: Wont fix Type: Bug Package: mcrypt related Operating System: windows PHP Version: 5.6.0beta2 Block user comment: N Private report: N New Comment: The warning was added to prevent usage of encryption primitives with malformed key data. It's there to catch code like the one you have provided, where use of incorrect keys compromises the security of the entire encryption. It won't be going away. Btw, just so it has been said, the key you are using has several issues: * You are using hex output of md5, instead of binary output. Effectively this means that you're loosing half of the entropy. * You are using md5 as a KDF - unless you already pass strong keying material to it, this is by no means safe - if you need to start off weak keying material, the use of PBKDF2 or similar is required. * I assume that you are not actually passing a 6 character string to md5, but if you do, that's way too short. E.g. a random base64 string with 6 characters only has 36 bits of entropy. Furthermore you're using the insecure ECB block chaining mode. Previous Comments: ------------------------------------------------------------------------ [2014-05-15 16:37:04] levim@php.net Bug 67287 is a duplicate of this one. ------------------------------------------------------------------------ [2014-05-15 14:49:27] mengxiangbaidu at qq dot com Description: ------------ php version <= 5.5.12 string(6) "zxcvbn" Warning: mcrypt_encrypt(): Key of size 32 not supported by this algorithm. in /test.php on line 9 Warning: mcrypt_decrypt(): Key of size 32 not supported by this algorithm. in /test.php on line 17 string(0) "zxcvbn" php version >= 5.6 string(6) "zxcvbn" Warning: mcrypt_encrypt(): Key of size 32 not supported by this algorithm. Only keys of size 24 supported in /test.php on line 9 Warning: mcrypt_decrypt(): Key of size 32 not supported by this algorithm. Only keys of size 24 supported in /test.php on line 17 string(0) "" ================ I know this warning is good thing 。 If you are upgrading php 5.5 to 5.6 , the php program does not work 。This maybe a serious problem。 Test script: --------------- <?php function encrypt($data, $key) { $block = mcrypt_get_block_size(MCRYPT_TRIPLEDES, MCRYPT_MODE_ECB); $pad = $block - (strlen($data) % $block); $data .= str_repeat(chr($pad), $pad); $iv = mcrypt_create_iv(mcrypt_get_iv_size(MCRYPT_TRIPLEDES, MCRYPT_MODE_ECB), MCRYPT_RAND); $encrypted = mcrypt_encrypt(MCRYPT_TRIPLEDES, $key, $data, MCRYPT_MODE_ECB, $iv); return $encrypted; } function decrypt($data, $key) { $iv = mcrypt_create_iv(mcrypt_get_iv_size(MCRYPT_TRIPLEDES, MCRYPT_MODE_ECB), MCRYPT_RAND); $data = mcrypt_decrypt(MCRYPT_TRIPLEDES, $key, $data, MCRYPT_MODE_ECB, $iv); $block = mcrypt_get_block_size(MCRYPT_TRIPLEDES, MCRYPT_MODE_ECB); $pad = ord($data[($len = strlen($data)) - 1]); $decrypted = substr($data, 0, strlen($data) - $pad); return rtrim($decrypted); } $key = md5('asdfgh'); $original_data = 'zxcvbn'; var_dump($original_data); $data = encrypt($original_data, $key); $data = base64_encode($data); $data = base64_decode($data); $data = decrypt($data, $key); var_dump($data); Expected result: ---------------- string(6) "zxcvbn" Warning: mcrypt_encrypt(): Key of size 32 not supported by this algorithm. Only keys of size 24 supported in /test.php on line 9 Warning: mcrypt_decrypt(): Key of size 32 not supported by this algorithm. Only keys of size 24 supported in /test.php on line 17 string(0) "zxcvbn" Actual result: -------------- string(6) "zxcvbn" Warning: mcrypt_encrypt(): Key of size 32 not supported by this algorithm. Only keys of size 24 supported in /test.php on line 9 Warning: mcrypt_decrypt(): Key of size 32 not supported by this algorithm. Only keys of size 24 supported in /test.php on line 17 string(0) "" ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67286&edit=1

« previous php.bugs (#185835) next »