PHP 4.0 Bug #5821: crypt() with blowfish fails

From: Date: Thu, 27 Jul 2000 17:11:20 +0000
Subject: PHP 4.0 Bug #5821: crypt() with blowfish fails
Groups: php.dev 
Request: Send a blank email to php-dev+get-26514@lists.php.net to get a copy of this message
From: cjc5@po.cwru.edu Operating system: OpenBSD 2.6,2.7 PHP version: 4.0.0 PHP Bug Type: Scripting Engine problem Bug description: crypt() with blowfish fails When I run the following code not only does crypt not return the correct encryption for the input (correct based on using C/Perl interface to libc crypt function), but it returns "random" output (crypted value changes on reloads). <?php $pwd='testtesttesttest'; $crypted='$2a$07$XRys.kixNfRTWuxNxKrrROOsCgOsdjjKIFtzZB49aybSBJGUV./Ky'; echo "$pwd<br>$crypted<br>\n"; echo crypt ($pwd, $crypted), "<br>\n"; // Why is this the same as above? echo crypt ($pwd, substr ($crypted,0,7)), "<br>\n"; ?> A quick glimpse at the code for crypt does not show an obvious error except for the fact that the salt gets truncated. However this is not sufficient to explain why when I truncate the salt to 7 char I get the same result. Note that OpenBSD uses $2a to signify blowfish in passwords, not $2$ as suggested in the docs. However, if I used $2$ instead I get the same results.

« previous php.dev (#26514) next »