Bug #76842 [Com]: password_verify returns true comparing null and \0
| From: | divinity76 at gmail dot com | Date: | Sat, 09 Oct 2021 13:04:25 +0000 |
| Subject: | Bug #76842 [Com]: password_verify returns true comparing null and \0 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-237113@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76842&edit=1
ID: 76842
Comment by: divinity76 at gmail dot com
Reported by: leon at valkenb dot org
Summary: password_verify returns true comparing null and \0
Status: Verified
Type: Bug
Package: *Encryption and hash functions
Operating System: Ubuntu
PHP Version: 7.1.21
Block user comment: N
Private report: N
New Comment:
this is a strict_types-related issue, enable strict_types=1 to get a proper error message and see
what's going on: the null is converted to string before password_hash gets to see the input
argument.
albeit, IMO, both password_hash and password_verify should throw an
InvalidArgumentException/ValueError/something when receiving a password-containing-null-bytes, as
those retards use C-style strings and incorrectly believes that the passwords "foo\x00bar"
and "foo\x00pizza" is the same password... but that should get its own issue
Previous Comments:
------------------------------------------------------------------------
[2018-12-06 22:32:33] leon at valkenb dot org
....
Given this is not that likely to be an issue, i have seen production databases that have gone and
encrypted raw password with password_hash() and many values were null, an i was able to log into the
sites knowing the email address and passing a string of nulls as the password.
------------------------------------------------------------------------
[2018-12-02 05:01:19] stas@php.net
Doesn't seem to be likely scenario to have null as valid password.
------------------------------------------------------------------------
[2018-09-06 11:37:59] cmb@php.net
The following patch has been added/updated:
Patch Name: password-as-path
Revision: 1536233879
URL: https://bugs.php.net/patch-display.php?bug=76842&patch=password-as-path&revision=1536233879
------------------------------------------------------------------------
[2018-09-06 11:37:54] cmb@php.net
> Is there any way i can see ug #74473 as its marked private?
No, sorry. Security reports are private to the reporter, and to
those with sec karma.
Anyhow, on a closer look I'm not sure this is really a bug at all.
password_hash()ing NULL is equivalent to password_hash()ing an
empty string, and this should be checked and prohibited in the
first place in userland (âpassword too shortâ). I consider it
unlikely that a user would circumvent this check by passing a
string of NULs.
Nonetheless, the password API should probably check for NUL bytes
in given passwords to prohibit such misuse.
------------------------------------------------------------------------
[2018-09-05 20:34:32] leon at valkenb dot org
Is there any way i can see ug #74473 as its marked private?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=76842
--
Edit this bug report at https://bugs.php.net/bug.php?id=76842&edit=1