Doc #66564 [Asn]: crypt() seems to silently discard input after a certain length

From: Date: Fri, 24 Jan 2014 00:07:51 +0000
Subject: Doc #66564 [Asn]: crypt() seems to silently discard input after a certain length
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-10879@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66564&edit=1 ID: 66564 Updated by: googleguy@php.net Reported by: ss23 at ss23 dot geek dot nz Summary: crypt() seems to silently discard input after a certain length Status: Assigned Type: Documentation Problem Package: Documentation problem PHP Version: Irrelevant Assigned To: googleguy Block user comment: N Private report: N New Comment: Will assign to myself for now. Previous Comments: ------------------------------------------------------------------------ [2014-01-24 00:06:21] ss23 at ss23 dot geek dot nz Description: ------------ It seems there is a limit to the input length of the password/str parameter to crypt(), however this is not documented anywhere. This has profound security implications, and all users should be aware of the issue. My preference would be a warning/notice triggered when you exceed the length, as well as documentation on this. Test script: --------------- $long = str_repeat('a', 100); var_dump(crypt($long . "1", '$2y$04$saltysaltysaltysaltytt')); var_dump(crypt($long . "2", '$2y$04$saltysaltysaltysaltytt')); var_dump(crypt($long . "12", '$2y$04$saltysaltysaltysaltytt')); Expected result: ---------------- A different hash in each case Actual result: -------------- string(60) "$2y$04$saltysaltysaltysaltyte9usMwh4/IIx0al18sl5oEFVM2Z/XJ7q" string(60) "$2y$04$saltysaltysaltysaltyte9usMwh4/IIx0al18sl5oEFVM2Z/XJ7q" string(60) "$2y$04$saltysaltysaltysaltyte9usMwh4/IIx0al18sl5oEFVM2Z/XJ7q" ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66564&edit=1

« previous php.doc.bugs (#10879) next »