Bug #71918 [Com]: hash_pbkdf2() strips trailing \0 in $password

From: Date: Tue, 29 Mar 2016 12:27:52 +0000
Subject: Bug #71918 [Com]: hash_pbkdf2() strips trailing \0 in $password
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-200212@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71918&edit=1 ID: 71918 Comment by: gelenkig at runbox dot com Reported by: gelenkig at runbox dot com Summary: hash_pbkdf2() strips trailing \0 in $password Status: Open Type: Bug Package: hash related Operating System: Linux PHP Version: 5.5.33 Block user comment: N Private report: N New Comment: Same problem with openssl_pbkdf2(). If it's expected behaviour it must be documented. // all 3 variables contain the same hash. $h1 = openssl_pbkdf2("password", 'salt', 40, 1000, 'sha256'); $h2 = openssl_pbkdf2("password\0", 'salt', 40, 1000, 'sha256'); $h3 = openssl_pbkdf2("password\0\0", 'salt', 40, 1000, 'sha256'); // TRUE, TRUE - wrong. var_dump($h1===$h2, $h1===$h3); Previous Comments: ------------------------------------------------------------------------ [2016-03-29 12:25:13] gelenkig at runbox dot com Description: ------------ hash_pbkdf2() must return different hashes for different $password's but it returns the same hash no matter how many trailing NUL bytes $password has. Test script: --------------- // all 3 variables contain the same hash. $h1 = hash_pbkdf2('sha256', "password", 'salt', 1000); $h2 = hash_pbkdf2('sha256', "password\0", 'salt', 1000); $h3 = hash_pbkdf2('sha256', "password\0\0", 'salt', 1000); // prints TRUE, TRUE but it must be 3 separate hashes: FALSE, FALSE. var_dump($h1===$h2, $h1===$h3); Expected result: ---------------- hash of password !== hash of password\0 !== hash of password\0\0 !== ... ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71918&edit=1

« previous php.bugs (#200212) next »