Re: PHP 4.0 Bug #5821: crypt() with blowfish fails

From: Date: Thu, 27 Jul 2000 18:35:38 +0000
Subject: Re: PHP 4.0 Bug #5821: crypt() with blowfish fails
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-26551@lists.php.net to get a copy of this message
"Powell,Tim" writes: >I can't speak for the c function (although I suspect that it is the same) >but in perl crypt only uses a 2 char salt. So no matter how long you make >the salt, only the first two characters really count. No, it passes the salt on to the libc crypt which then decides what to do with it. The $2a (in the case of OpenBSD) flags blowfish. See http://www.openbsd.org/cgi-bin/man.cgi?query=crypt&apropos=0&sektion=0&manpath=OpenBSD+Current&arch=i386&format=html for an online version of the manpage. Note that it says that the whole string (here we are calling it the salt) is to be passed for interpretation. Craig

« previous php.dev (#26551) next »