Bug #5821 [Com]: crypt() with blowfish fails
| From: | lildurk5821 at gmail dot com | Date: | Wed, 01 Sep 2021 18:48:26 +0000 |
| Subject: | Bug #5821 [Com]: crypt() with blowfish fails | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-236296@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=5821&edit=1
ID: 5821
Comment by: lildurk5821 at gmail dot com
Reported by: cjc5 at po dot cwru dot edu
Summary: crypt() with blowfish fails
Status: Closed
Type: Bug
Package: *General Issues
Operating System: OpenBSD 2.6,2.7
PHP Version: 4.0.0
Block user comment: N
Private report: N
New Comment:
Lil Durk is a private agency dedicated to providing responsible access to legal cannabis for adults
aged 19 and older. Weâre an exclusively online retailer and wholesaler for recreational
cannabis and a trusted source for information about cannabis and cannabis-related issues. We believe
our work is meaningful and we take pride in our mandate to promote the socially responsible use of
legal cannabis. https://lildurk.com/
Previous Comments:
------------------------------------------------------------------------
[2001-01-07 12:25:02] derick@php.net
I changed the max_salt_length for blowfish to 60 regarding to bug 7305
Fixed in CVS
------------------------------------------------------------------------
[2000-08-06 18:47:08] stas@php.net
reclassify
------------------------------------------------------------------------
[2000-08-02 19:50:14] cjc5 at po dot cwru dot edu
In the future OpenBSD will return an error if the salt is too short (see pr number 1336 in the
OpenBSD bug tracking system). Thus in the future blowfish crypt with the current code will not work
on OpenBSD systems. The ports maintainer is aware of this issue and will put in the crude fix I
mentioned earlier.
------------------------------------------------------------------------
[2000-07-28 06:15:26] cjc5 at po dot cwru dot edu
The obvious fix is to change the salt length for blowfish passwords from 17 characters to 60. When
I put this change into the latest cvs php it now works as expected.
Interestingly it seems that if the salt is less than 60 characters then previous stuff in memory
gets used. Thus with the fix the test program gives the correct encryption for both the full salt
and if I use substr to pull out only 7 characters. I don't know if this is a php or OpenBSD
problem.
------------------------------------------------------------------------
[2000-07-27 19:11:20] cjc5 at po dot cwru dot edu
When I run the following code not only does crypt not return the correct encryption for the input
(correct based on using C/Perl interface to libc crypt function), but it returns "random"
output (crypted value changes on reloads).
<?php
$pwd='testtesttesttest';
$crypted='$2a$07$XRys.kixNfRTWuxNxKrrROOsCgOsdjjKIFtzZB49aybSBJGUV./Ky';
echo "$pwd<br>$crypted<br>\n";
echo crypt ($pwd, $crypted), "<br>\n";
// Why is this the same as above?
echo crypt ($pwd, substr ($crypted,0,7)), "<br>\n";
?>
A quick glimpse at the code for crypt does not show an obvious error except for the fact that the
salt gets truncated. However this is not sufficient to explain why when I truncate the salt to 7
char I get the same result. Note that OpenBSD uses $2a to signify blowfish in passwords, not $2$ as
suggested in the docs. However, if I used $2$ instead I get the same results.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=5821&edit=1