#36937 [NEW]: key length too long distroys the hash
| From: | dragos at codersnest dot com | Date: | Fri, 31 Mar 2006 18:35:32 +0000 |
| Subject: | #36937 [NEW]: key length too long distroys the hash | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-95173@lists.php.net to get a copy of this message | ||
From: dragos at codersnest dot com
Operating system: Suse 9.3 + Windoze XP
PHP version: 4.4.2
PHP Bug Type: mhash related
Bug description: key length too long distroys the hash
Description:
------------
I tried to do a gateway script which required me to send a hash(SHA1) of
some given data, with a given key. In the beginning it worked, then after
we switched to production, the key changed length from 32 to 194 (hex
chars). The key was calculated as pack() binary value from the original
key. At this point, the value returned by mhash() got wrong. So,
basically, I am assuming that there is somewhere a constraint on the key
length, either on pack() there might be a problem, though i've used that
one before.
Reproduce code:
---------------
example 1 (working):
$data = 'some string data';
$mkey = '00112233445566778899AABBCCDDEEFF';
$mac = bin2hex(mhash(MHASH_SHA1,$mac,pack('h*',$mkey)));
This was working!
example 2:
$mkey='496E7465726E6574206765626F72656E2C20656E747769636B656C7420756E6420756D67657365747A742E20656E7465727061796D656E74206661737374206469652067846E6769677374656E205A61686C617274656E20696E2065696E656D20';
This was not workign anymore!
Expected result:
----------------
a correct hash value which to be checked at the gateway again by
calculating the same hash from fields of a form..
Actual result:
--------------
bad hash value
--
Edit bug report at http://bugs.php.net/?id=36937&edit=1
--
Try a CVS snapshot (PHP 4.4): http://bugs.php.net/fix.php?id=36937&r=trysnapshot44
Try a CVS snapshot (PHP 5.1): http://bugs.php.net/fix.php?id=36937&r=trysnapshot51
Try a CVS snapshot (PHP 6.0): http://bugs.php.net/fix.php?id=36937&r=trysnapshot60
Fixed in CVS: http://bugs.php.net/fix.php?id=36937&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=36937&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=36937&r=needtrace
Need Reproduce Script: http://bugs.php.net/fix.php?id=36937&r=needscript
Try newer version: http://bugs.php.net/fix.php?id=36937&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=36937&r=support
Expected behavior: http://bugs.php.net/fix.php?id=36937&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=36937&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=36937&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=36937&r=globals
PHP 3 support discontinued: http://bugs.php.net/fix.php?id=36937&r=php3
Daylight Savings: http://bugs.php.net/fix.php?id=36937&r=dst
IIS Stability: http://bugs.php.net/fix.php?id=36937&r=isapi
Install GNU Sed: http://bugs.php.net/fix.php?id=36937&r=gnused
Floating point limitations: http://bugs.php.net/fix.php?id=36937&r=float
No Zend Extensions: http://bugs.php.net/fix.php?id=36937&r=nozend
MySQL Configuration Error: http://bugs.php.net/fix.php?id=36937&r=mysqlcfg