Re: note 8339 added to crypt
| From: | Ron Chmara | Date: | Thu, 07 Sep 2000 04:20:20 +0000 |
| Subject: | Re: note 8339 added to crypt | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32485@lists.php.net to get a copy of this message | ||
bene@php2.chek.com wrote:
> "If the salt argument is not provided, it will be randomly generated by PHP."
> This statement is FALSE. As of 4.01pl2, ONE random salt is created... meaning that if you
> recursively run the crypt() you will be using the same salt. This can be a feature in RARE
> situations, but I recommend that you create your own random code to make
> a salt.
> http://www.php.net/manual/function.crypt.php
See also bug 5821.
Shall I redocument, to indicate the possible security issue and the repeating
salt?
-Bop
--
Brought to you from iBop the iMac, a MacOS, Win95, Win98, LinuxPPC machine,
which is currently in MacOS land. Your bopping may vary.