Bug #76842 [Ver]: password_verify returns true comparing null and \0

From: Date: Thu, 06 Dec 2018 22:32:33 +0000
Subject: Bug #76842 [Ver]: password_verify returns true comparing null and \0
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218301@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76842&edit=1 ID: 76842 User updated by: leon at valkenb dot org Reported by: leon at valkenb dot org Summary: password_verify returns true comparing null and \0 Status: Verified Type: Bug Package: *Encryption and hash functions Operating System: Ubuntu PHP Version: 7.1.21 Block user comment: N Private report: N New Comment: .... Given this is not that likely to be an issue, i have seen production databases that have gone and encrypted raw password with password_hash() and many values were null, an i was able to log into the sites knowing the email address and passing a string of nulls as the password. Previous Comments: ------------------------------------------------------------------------ [2018-12-02 05:01:19] stas@php.net Doesn't seem to be likely scenario to have null as valid password. ------------------------------------------------------------------------ [2018-09-06 11:37:59] cmb@php.net The following patch has been added/updated: Patch Name: password-as-path Revision: 1536233879 URL: https://bugs.php.net/patch-display.php?bug=76842&patch=password-as-path&revision=1536233879 ------------------------------------------------------------------------ [2018-09-06 11:37:54] cmb@php.net > Is there any way i can see ug #74473 as its marked private? No, sorry. Security reports are private to the reporter, and to those with sec karma. Anyhow, on a closer look I'm not sure this is really a bug at all. password_hash()ing NULL is equivalent to password_hash()ing an empty string, and this should be checked and prohibited in the first place in userland (“password too short”). I consider it unlikely that a user would circumvent this check by passing a string of NULs. Nonetheless, the password API should probably check for NUL bytes in given passwords to prohibit such misuse. ------------------------------------------------------------------------ [2018-09-05 20:34:32] leon at valkenb dot org Is there any way i can see ug #74473 as its marked private? ------------------------------------------------------------------------ [2018-09-05 10:35:18] cmb@php.net This might be related to bug #74473. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=76842 -- Edit this bug report at https://bugs.php.net/bug.php?id=76842&edit=1

« previous php.bugs (#218301) next »