Bug #73058 [Ver->Csd]: crypt broken when salt is 'too' long
| From: | ab@php.net | Date: | Sat, 10 Sep 2016 01:18:50 +0000 |
| Subject: | Bug #73058 [Ver->Csd]: crypt broken when salt is 'too' long | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-203937@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73058&edit=1
ID: 73058
Updated by: ab@php.net
Reported by: sjon at hortensius dot net
Summary: crypt broken when salt is 'too' long
-Status: Verified
+Status: Closed
Type: Bug
Package: hash related
PHP Version: 7.1.0RC1
Assigned To: ab
Block user comment: N
Private report: N
New Comment:
Christoph,
yeah, that's a better approach. I also completely forgot about the hacks with '$' in
crypt(). Re-fixed with 669fda00b75a0d361810429e0ef53f6c740b1727.
Thanks.
Previous Comments:
------------------------------------------------------------------------
[2016-09-09 15:22:29] cmb@php.net
Indeed, Damian.
Anatol, with regard to the fix[1]: it seems to me, that it would
suffice to check that the actual salt is not empty, i.e. to do the
following instead:
if (salt[7] == '$') {
return NULL;
}
[1] <https://github.com/php/php-src/commit/295303b5>
------------------------------------------------------------------------
[2016-09-09 14:23:34] requinix@php.net
Looks like it was caused by the fix for bug #72703.
https://github.com/php/php-src/commit/295303b59059536079caf68b4d76acf2149bd42c
------------------------------------------------------------------------
[2016-09-09 13:35:07] sjon at hortensius dot net
Description:
------------
$pass = 'secret';
$salt = '$2y$07$usesomesillystringforsalt$';
var_dump(crypt($pass, $salt));
* as demonstrated on https://3v4l.org/kuAJO
Test script:
---------------
* works with shorter salt: https://3v4l.org/O654F
* fails with longer salt: https://3v4l.org/dvgnq (includes
CRYPT_SALT_LENGTH)
Expected result:
----------------
string(60) "$2y$07$usesomesillystringforex.u2VJUMLRWaJNuw0Hu2FvCEimdeYVO"
Actual result:
--------------
string(2) "*0"
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73058&edit=1