Bug #70444 [Opn->Nab]: Produces same cipher for different string with same salt
| From: | requinix@php.net | Date: | Mon, 07 Sep 2015 09:47:21 +0000 |
| Subject: | Bug #70444 [Opn->Nab]: Produces same cipher for different string with same salt | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-195829@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70444&edit=1
ID: 70444
Updated by: requinix@php.net
Reported by: sunshine dot cst dot 07 at gmail dot com
Summary: Produces same cipher for different string with same
salt
-Status: Open
+Status: Not a bug
Type: Bug
Package: *Encryption and hash functions
Operating System: Windows 7 Enterprise - 64bit
PHP Version: 5.5.29
Block user comment: N
Private report: N
New Comment:
As @phpmpan said, by using "12" as the salt (the rest is irrelevant) you've selected
the "standard DES-based hash", and
> The standard DES-based crypt() returns the salt as the first two characters of
> the output. It also only uses the first eight characters of str, so longer
> strings that start with the same eight characters will generate the same result
> (when the same salt is used).
If you don't know what you're doing with crypt() then use the password hashing functions
instead.
http://php.net/manual/en/ref.password.php
Previous Comments:
------------------------------------------------------------------------
[2015-09-07 09:40:47] phpmpan at mpan dot pl
This is a hash. Hashes are expected to have collisions. However, nice finding.
Also:
/ Standard DES-based hash with a **two character salt**
from the alphabet "./0-9A-Za-z". /
/ password_hash() uses a strong hash, generates a strong salt,
and applies proper rounds automatically. password_hash() is
a simple crypt() wrapper and compatible with existing
password hashes. Use of password_hash() is encouraged. /
-- <https://secure.php.net/manual/en/function.crypt.php>
------------------------------------------------------------------------
[2015-09-07 09:21:33] sunshine dot cst dot 07 at gmail dot com
Description:
------------
---
From manual page: http://www.php.net/intro.password
---
While using "crypt($password, $salt)" function for two different strings with same $salt,
it returns same encrypted text.
Test script:
---------------
$email = "bforbiswajit@outlook.com";
$password = "biswajit"; //use "biswajit123" and it gives same cipher
$salt = "1234";
$saltedPassword = crypt($password, $salt);
echo $saltedPassword;
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70444&edit=1