Bug #5821 [Com]: crypt() with blowfish fails

From: Date: Wed, 01 Sep 2021 18:48:26 +0000
Subject: Bug #5821 [Com]: crypt() with blowfish fails
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-236296@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=5821&edit=1 ID: 5821 Comment by: lildurk5821 at gmail dot com Reported by: cjc5 at po dot cwru dot edu Summary: crypt() with blowfish fails Status: Closed Type: Bug Package: *General Issues Operating System: OpenBSD 2.6,2.7 PHP Version: 4.0.0 Block user comment: N Private report: N New Comment: Lil Durk is a private agency dedicated to providing responsible access to legal cannabis for adults aged 19 and older. We’re an exclusively online retailer and wholesaler for recreational cannabis and a trusted source for information about cannabis and cannabis-related issues. We believe our work is meaningful and we take pride in our mandate to promote the socially responsible use of legal cannabis. https://lildurk.com/ Previous Comments: ------------------------------------------------------------------------ [2001-01-07 12:25:02] derick@php.net I changed the max_salt_length for blowfish to 60 regarding to bug 7305 Fixed in CVS ------------------------------------------------------------------------ [2000-08-06 18:47:08] stas@php.net reclassify ------------------------------------------------------------------------ [2000-08-02 19:50:14] cjc5 at po dot cwru dot edu In the future OpenBSD will return an error if the salt is too short (see pr number 1336 in the OpenBSD bug tracking system). Thus in the future blowfish crypt with the current code will not work on OpenBSD systems. The ports maintainer is aware of this issue and will put in the crude fix I mentioned earlier. ------------------------------------------------------------------------ [2000-07-28 06:15:26] cjc5 at po dot cwru dot edu The obvious fix is to change the salt length for blowfish passwords from 17 characters to 60. When I put this change into the latest cvs php it now works as expected. Interestingly it seems that if the salt is less than 60 characters then previous stuff in memory gets used. Thus with the fix the test program gives the correct encryption for both the full salt and if I use substr to pull out only 7 characters. I don't know if this is a php or OpenBSD problem. ------------------------------------------------------------------------ [2000-07-27 19:11:20] cjc5 at po dot cwru dot edu When I run the following code not only does crypt not return the correct encryption for the input (correct based on using C/Perl interface to libc crypt function), but it returns "random" output (crypted value changes on reloads). <?php $pwd='testtesttesttest'; $crypted='$2a$07$XRys.kixNfRTWuxNxKrrROOsCgOsdjjKIFtzZB49aybSBJGUV./Ky'; echo "$pwd<br>$crypted<br>\n"; echo crypt ($pwd, $crypted), "<br>\n"; // Why is this the same as above? echo crypt ($pwd, substr ($crypted,0,7)), "<br>\n"; ?> A quick glimpse at the code for crypt does not show an obvious error except for the fact that the salt gets truncated. However this is not sufficient to explain why when I truncate the salt to 7 char I get the same result. Note that OpenBSD uses $2a to signify blowfish in passwords, not $2$ as suggested in the docs. However, if I used $2$ instead I get the same results. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=5821&edit=1

« previous php.bugs (#236296) next »