PHP 4.0 Bug #5821: crypt() with blowfish fails
| From: | cjc5 at po dot cwru dot edu | Date: | Thu, 27 Jul 2000 17:11:20 +0000 |
| Subject: | PHP 4.0 Bug #5821: crypt() with blowfish fails | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-26514@lists.php.net to get a copy of this message | ||
From: cjc5@po.cwru.edu
Operating system: OpenBSD 2.6,2.7
PHP version: 4.0.0
PHP Bug Type: Scripting Engine problem
Bug description: crypt() with blowfish fails
When I run the following code not only does crypt not return the correct encryption for the input
(correct based on using C/Perl interface to libc crypt function), but it returns "random"
output (crypted value changes on reloads).
<?php
$pwd='testtesttesttest';
$crypted='$2a$07$XRys.kixNfRTWuxNxKrrROOsCgOsdjjKIFtzZB49aybSBJGUV./Ky';
echo "$pwd<br>$crypted<br>\n";
echo crypt ($pwd, $crypted), "<br>\n";
// Why is this the same as above?
echo crypt ($pwd, substr ($crypted,0,7)), "<br>\n";
?>
A quick glimpse at the code for crypt does not show an obvious error except for the fact that the
salt gets truncated. However this is not sufficient to explain why when I truncate the salt to 7
char I get the same result. Note that OpenBSD uses $2a to signify blowfish in passwords, not $2$ as
suggested in the docs. However, if I used $2$ instead I get the same results.