Doc #66564 [Asn]: crypt() seems to silently discard input after a certain length

From: Date: Tue, 28 Jan 2014 10:29:10 +0000
Subject: Doc #66564 [Asn]: crypt() seems to silently discard input after a certain length
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-10900@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66564&edit=1 ID: 66564 Updated by: googleguy@php.net Reported by: ss23 at ss23 dot geek dot nz Summary: crypt() seems to silently discard input after a certain length Status: Assigned Type: Documentation Problem Package: Documentation problem PHP Version: Irrelevant Assigned To: googleguy Block user comment: N Private report: N New Comment: It seems that input from the $str argument of crypt will truncate at exactly 73 characters when using CRYPT_BLOWFISH $salt. password_hash, is obviously also affected in the same way. Tested on release bracnhes of 5.3.0 through 5.6.0alpha1 with 3v4l.org and independently on my own system. Reproducible results for crypt: http://3v4l.org/3icqi Reproducible results for password_hash: http://3v4l.org/GbOo4 Reference to php-src http://lxr.php.net/xref/PHP_5_5/ext/standard/crypt_blowfish.c#819 Will update the documentation to reflect this limit more clearly in the documentation since it is defined behavior. Previous Comments: ------------------------------------------------------------------------ [2014-01-24 00:07:51] googleguy@php.net Will assign to myself for now. ------------------------------------------------------------------------ [2014-01-24 00:06:21] ss23 at ss23 dot geek dot nz Description: ------------ It seems there is a limit to the input length of the password/str parameter to crypt(), however this is not documented anywhere. This has profound security implications, and all users should be aware of the issue. My preference would be a warning/notice triggered when you exceed the length, as well as documentation on this. Test script: --------------- $long = str_repeat('a', 100); var_dump(crypt($long . "1", '$2y$04$saltysaltysaltysaltytt')); var_dump(crypt($long . "2", '$2y$04$saltysaltysaltysaltytt')); var_dump(crypt($long . "12", '$2y$04$saltysaltysaltysaltytt')); Expected result: ---------------- A different hash in each case Actual result: -------------- string(60) "$2y$04$saltysaltysaltysaltyte9usMwh4/IIx0al18sl5oEFVM2Z/XJ7q" string(60) "$2y$04$saltysaltysaltysaltyte9usMwh4/IIx0al18sl5oEFVM2Z/XJ7q" string(60) "$2y$04$saltysaltysaltysaltyte9usMwh4/IIx0al18sl5oEFVM2Z/XJ7q" ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66564&edit=1

« previous php.doc.bugs (#10900) next »