PHP 4.0 Bug #8834 Updated: crypt() starts from not random salt
| From: | sniper@php.net | Date: | Thu, 05 Apr 2001 18:57:45 +0000 |
| Subject: | PHP 4.0 Bug #8834 Updated: crypt() starts from not random salt | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-50965@lists.php.net to get a copy of this message | ||
ID: 8834
Updated by: sniper
Reported By: muhlig@us.edu.pl
Old-Status: Open
Status: Feedback
Bug Type: Strings related
Assigned To:
Comments:
This is most likely a Solaris specific issue as I can't
reproduce this on Linux.
Can you please include the output of this command in both
Solaris 2.4 and 2.6 (in php4):
# grep RAND main/php_config.h
It might be that in both of those system the seed generator
found is srand() which isn't so good as srandom() is.
But I also found (with google :) that srandom() might not be
that good either (in Solaris) so that leaves us with a problem.
One solution might be that we run php_srand() in RINIT instead of MINIT when Solaris is used.
--Jani
Previous Comments:
---------------------------------------------------------------------------
[2001-01-22 06:05:34] muhlig@us.edu.pl
PHP compiled as Apache module. Look like crypt() starts from not random salt. In case of my Solaris
2.4, first crypt() call always generates string starting from "IH". In case of Solaris 2.6
it always starts from "C.".
Looks like in every instantiation of new Apache process PHP starts crypt from the same salt value.
In the same process next crypt() calls look like they generate random strings, though. But next
process restarts with the same value.
---------------------------------------------------------------------------
ATTENTION! Do NOT reply to this email!
To reply, use the web interface found at http://bugs.php.net/?id=8834&edit=2