Doc #66564 [Asn]: crypt() seems to silently discard input after a certain length
| From: | googleguy@php.net | Date: | Fri, 24 Jan 2014 00:07:51 +0000 |
| Subject: | Doc #66564 [Asn]: crypt() seems to silently discard input after a certain length | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-10879@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66564&edit=1
ID: 66564
Updated by: googleguy@php.net
Reported by: ss23 at ss23 dot geek dot nz
Summary: crypt() seems to silently discard input after a
certain length
Status: Assigned
Type: Documentation Problem
Package: Documentation problem
PHP Version: Irrelevant
Assigned To: googleguy
Block user comment: N
Private report: N
New Comment:
Will assign to myself for now.
Previous Comments:
------------------------------------------------------------------------
[2014-01-24 00:06:21] ss23 at ss23 dot geek dot nz
Description:
------------
It seems there is a limit to the input length of the password/str parameter to crypt(), however this
is not documented anywhere.
This has profound security implications, and all users should be aware of the issue.
My preference would be a warning/notice triggered when you exceed the length, as well as
documentation on this.
Test script:
---------------
$long = str_repeat('a', 100);
var_dump(crypt($long . "1", '$2y$04$saltysaltysaltysaltytt'));
var_dump(crypt($long . "2", '$2y$04$saltysaltysaltysaltytt'));
var_dump(crypt($long . "12", '$2y$04$saltysaltysaltysaltytt'));
Expected result:
----------------
A different hash in each case
Actual result:
--------------
string(60) "$2y$04$saltysaltysaltysaltyte9usMwh4/IIx0al18sl5oEFVM2Z/XJ7q"
string(60) "$2y$04$saltysaltysaltysaltyte9usMwh4/IIx0al18sl5oEFVM2Z/XJ7q"
string(60) "$2y$04$saltysaltysaltysaltyte9usMwh4/IIx0al18sl5oEFVM2Z/XJ7q"
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66564&edit=1