Bug #70444 [Com]: Produces same cipher for different string with same salt
| From: | phpmpan at mpan dot pl | Date: | Mon, 07 Sep 2015 09:40:53 +0000 |
| Subject: | Bug #70444 [Com]: Produces same cipher for different string with same salt | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-195828@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70444&edit=1
ID: 70444
Comment by: phpmpan at mpan dot pl
Reported by: sunshine dot cst dot 07 at gmail dot com
Summary: Produces same cipher for different string with same
salt
Status: Open
Type: Bug
Package: *Encryption and hash functions
Operating System: Windows 7 Enterprise - 64bit
PHP Version: 5.5.29
Block user comment: N
Private report: N
New Comment:
This is a hash. Hashes are expected to have collisions. However, nice finding.
Also:
/ Standard DES-based hash with a **two character salt**
from the alphabet "./0-9A-Za-z". /
/ password_hash() uses a strong hash, generates a strong salt,
and applies proper rounds automatically. password_hash() is
a simple crypt() wrapper and compatible with existing
password hashes. Use of password_hash() is encouraged. /
-- <https://secure.php.net/manual/en/function.crypt.php>
Previous Comments:
------------------------------------------------------------------------
[2015-09-07 09:21:33] sunshine dot cst dot 07 at gmail dot com
Description:
------------
---
From manual page: http://www.php.net/intro.password
---
While using "crypt($password, $salt)" function for two different strings with same $salt,
it returns same encrypted text.
Test script:
---------------
$email = "bforbiswajit@outlook.com";
$password = "biswajit"; //use "biswajit123" and it gives same cipher
$salt = "1234";
$saltedPassword = crypt($password, $salt);
echo $saltedPassword;
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70444&edit=1