Doc #66564 [Asn]: crypt() seems to silently discard input after a certain length
| From: | googleguy@php.net | Date: | Tue, 28 Jan 2014 10:29:10 +0000 |
| Subject: | Doc #66564 [Asn]: crypt() seems to silently discard input after a certain length | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-10900@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66564&edit=1
ID: 66564
Updated by: googleguy@php.net
Reported by: ss23 at ss23 dot geek dot nz
Summary: crypt() seems to silently discard input after a
certain length
Status: Assigned
Type: Documentation Problem
Package: Documentation problem
PHP Version: Irrelevant
Assigned To: googleguy
Block user comment: N
Private report: N
New Comment:
It seems that input from the $str argument of crypt will truncate at exactly 73 characters when
using CRYPT_BLOWFISH $salt. password_hash, is obviously also affected in the same way.
Tested on release bracnhes of 5.3.0 through 5.6.0alpha1 with 3v4l.org and independently on my own
system.
Reproducible results for crypt:
http://3v4l.org/3icqi
Reproducible results for password_hash:
http://3v4l.org/GbOo4
Reference to php-src
http://lxr.php.net/xref/PHP_5_5/ext/standard/crypt_blowfish.c#819
Will update the documentation to reflect this limit more clearly in the documentation since it is
defined behavior.
Previous Comments:
------------------------------------------------------------------------
[2014-01-24 00:07:51] googleguy@php.net
Will assign to myself for now.
------------------------------------------------------------------------
[2014-01-24 00:06:21] ss23 at ss23 dot geek dot nz
Description:
------------
It seems there is a limit to the input length of the password/str parameter to crypt(), however this
is not documented anywhere.
This has profound security implications, and all users should be aware of the issue.
My preference would be a warning/notice triggered when you exceed the length, as well as
documentation on this.
Test script:
---------------
$long = str_repeat('a', 100);
var_dump(crypt($long . "1", '$2y$04$saltysaltysaltysaltytt'));
var_dump(crypt($long . "2", '$2y$04$saltysaltysaltysaltytt'));
var_dump(crypt($long . "12", '$2y$04$saltysaltysaltysaltytt'));
Expected result:
----------------
A different hash in each case
Actual result:
--------------
string(60) "$2y$04$saltysaltysaltysaltyte9usMwh4/IIx0al18sl5oEFVM2Z/XJ7q"
string(60) "$2y$04$saltysaltysaltysaltyte9usMwh4/IIx0al18sl5oEFVM2Z/XJ7q"
string(60) "$2y$04$saltysaltysaltysaltyte9usMwh4/IIx0al18sl5oEFVM2Z/XJ7q"
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66564&edit=1