RE: [PHP-DEV] PHP 4.0 Bug #5821: crypt() with blowfish fails
| From: | Powell,Tim | Date: | Thu, 27 Jul 2000 18:29:52 +0000 |
| Subject: | RE: [PHP-DEV] PHP 4.0 Bug #5821: crypt() with blowfish fails | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-26547@lists.php.net to get a copy of this message | ||
I can't speak for the c function (although I suspect that it is the same)
but in perl crypt only uses a 2 char salt. So no matter how long you make
the salt, only the first two characters really count.
Tim
-----Original Message-----
From: cjc5@po.cwru.edu [mailto:cjc5@po.cwru.edu]
Sent: Thursday, July 27, 2000 1:11 PM
To: php-dev@lists.php.net
Subject: [PHP-DEV] PHP 4.0 Bug #5821: crypt() with blowfish fails
From: cjc5@po.cwru.edu
Operating system: OpenBSD 2.6,2.7
PHP version: 4.0.0
PHP Bug Type: Scripting Engine problem
Bug description: crypt() with blowfish fails
When I run the following code not only does crypt not return the correct
encryption for the input (correct based on using C/Perl interface to libc
crypt function), but it returns "random" output (crypted value changes on
reloads).
<?php
$pwd='testtesttesttest';
$crypted='$2a$07$XRys.kixNfRTWuxNxKrrROOsCgOsdjjKIFtzZB49aybSBJGUV./Ky';
echo "$pwd<br>$crypted<br>\n";
echo crypt ($pwd, $crypted), "<br>\n";
// Why is this the same as above?
echo crypt ($pwd, substr ($crypted,0,7)), "<br>\n";
?>
A quick glimpse at the code for crypt does not show an obvious error except
for the fact that the salt gets truncated. However this is not sufficient
to explain why when I truncate the salt to 7 char I get the same result.
Note that OpenBSD uses $2a to signify blowfish in passwords, not $2$ as
suggested in the docs. However, if I used $2$ instead I get the same
results.
--
PHP Development Mailing List <http://www.php.net/>
To unsubscribe, e-mail: php-dev-unsubscribe@lists.php.net
For additional commands, e-mail: php-dev-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net