Bug #76842 [Com]: password_verify returns true comparing null and \0

From: Date: Sat, 09 Oct 2021 13:04:25 +0000
Subject: Bug #76842 [Com]: password_verify returns true comparing null and \0
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-237113@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76842&edit=1 ID: 76842 Comment by: divinity76 at gmail dot com Reported by: leon at valkenb dot org Summary: password_verify returns true comparing null and \0 Status: Verified Type: Bug Package: *Encryption and hash functions Operating System: Ubuntu PHP Version: 7.1.21 Block user comment: N Private report: N New Comment: this is a strict_types-related issue, enable strict_types=1 to get a proper error message and see what's going on: the null is converted to string before password_hash gets to see the input argument. albeit, IMO, both password_hash and password_verify should throw an InvalidArgumentException/ValueError/something when receiving a password-containing-null-bytes, as those retards use C-style strings and incorrectly believes that the passwords "foo\x00bar" and "foo\x00pizza" is the same password... but that should get its own issue Previous Comments: ------------------------------------------------------------------------ [2018-12-06 22:32:33] leon at valkenb dot org .... Given this is not that likely to be an issue, i have seen production databases that have gone and encrypted raw password with password_hash() and many values were null, an i was able to log into the sites knowing the email address and passing a string of nulls as the password. ------------------------------------------------------------------------ [2018-12-02 05:01:19] stas@php.net Doesn't seem to be likely scenario to have null as valid password. ------------------------------------------------------------------------ [2018-09-06 11:37:59] cmb@php.net The following patch has been added/updated: Patch Name: password-as-path Revision: 1536233879 URL: https://bugs.php.net/patch-display.php?bug=76842&patch=password-as-path&revision=1536233879 ------------------------------------------------------------------------ [2018-09-06 11:37:54] cmb@php.net > Is there any way i can see ug #74473 as its marked private? No, sorry. Security reports are private to the reporter, and to those with sec karma. Anyhow, on a closer look I'm not sure this is really a bug at all. password_hash()ing NULL is equivalent to password_hash()ing an empty string, and this should be checked and prohibited in the first place in userland (“password too short”). I consider it unlikely that a user would circumvent this check by passing a string of NULs. Nonetheless, the password API should probably check for NUL bytes in given passwords to prohibit such misuse. ------------------------------------------------------------------------ [2018-09-05 20:34:32] leon at valkenb dot org Is there any way i can see ug #74473 as its marked private? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=76842 -- Edit this bug report at https://bugs.php.net/bug.php?id=76842&edit=1

« previous php.bugs (#237113) next »