Bug #71918 [Com]: hash_pbkdf2() strips trailing \0 in $password
| From: | gelenkig at runbox dot com | Date: | Tue, 29 Mar 2016 12:27:52 +0000 |
| Subject: | Bug #71918 [Com]: hash_pbkdf2() strips trailing \0 in $password | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-200212@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71918&edit=1
ID: 71918
Comment by: gelenkig at runbox dot com
Reported by: gelenkig at runbox dot com
Summary: hash_pbkdf2() strips trailing \0 in $password
Status: Open
Type: Bug
Package: hash related
Operating System: Linux
PHP Version: 5.5.33
Block user comment: N
Private report: N
New Comment:
Same problem with openssl_pbkdf2(). If it's expected behaviour it must be documented.
// all 3 variables contain the same hash.
$h1 = openssl_pbkdf2("password", 'salt', 40, 1000, 'sha256');
$h2 = openssl_pbkdf2("password\0", 'salt', 40, 1000, 'sha256');
$h3 = openssl_pbkdf2("password\0\0", 'salt', 40, 1000, 'sha256');
// TRUE, TRUE - wrong.
var_dump($h1===$h2, $h1===$h3);
Previous Comments:
------------------------------------------------------------------------
[2016-03-29 12:25:13] gelenkig at runbox dot com
Description:
------------
hash_pbkdf2() must return different hashes for different $password's but it returns the same
hash no matter how many trailing NUL bytes $password has.
Test script:
---------------
// all 3 variables contain the same hash.
$h1 = hash_pbkdf2('sha256', "password", 'salt', 1000);
$h2 = hash_pbkdf2('sha256', "password\0", 'salt', 1000);
$h3 = hash_pbkdf2('sha256', "password\0\0", 'salt', 1000);
// prints TRUE, TRUE but it must be 3 separate hashes: FALSE, FALSE.
var_dump($h1===$h2, $h1===$h3);
Expected result:
----------------
hash of password !== hash of password\0 !== hash of password\0\0 !== ...
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71918&edit=1