Doc #62453 [NEW]: Terrible sample code

From: Date: Fri, 29 Jun 2012 23:49:49 +0000
Subject: Doc #62453 [NEW]: Terrible sample code
Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-8517@lists.php.net to get a copy of this message
From: maarten dot bodewes at gmail dot com Operating system: PHP version: 5.4.4 Package: Documentation problem Bug Type: Documentation Problem Bug description:Terrible sample code Description: ------------ --- From manual page: http://www.php.net/function.mcrypt-encrypt#refsect1-function.mcrypt-encrypt-examples --- Hi, I'm a security professional (+10 years experience). I'm wondering which arse wrote that PHP sample this bug is pointing at. The following mistakes are present (at the minimum): * using an IV with ECB encoding * using ECB at all for non random plain text * using ECB within an example in the first place * mistaking a passphrase with a key (keys should be random bytes of data, or at least generated using e.g. PBKDF2, bcrypt or scrypt) * supplying an incorrect number of characters for the key (25 if I'm not mistaken) * using MCRYPT_RIJNDAEL_256 instead of MCRYPT_RIJNDAEL_128 (AES) * not performing PKCS#7 padding by default If this sample is to coax unsuspecting people in writing insecure code which is not compatible with any crypto library out there, keep it in. Otherwise toss it out and start over again. -- Edit bug report at https://bugs.php.net/bug.php?id=62453&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=62453&r=trysnapshot54 Try a snapshot (PHP 5.3): https://bugs.php.net/fix.php?id=62453&r=trysnapshot53 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=62453&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=62453&r=fixed Fixed in SVN and need be documented: https://bugs.php.net/fix.php?id=62453&r=needdocs Fixed in release: https://bugs.php.net/fix.php?id=62453&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=62453&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=62453&r=needscript Try newer version: https://bugs.php.net/fix.php?id=62453&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=62453&r=support Expected behavior: https://bugs.php.net/fix.php?id=62453&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=62453&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=62453&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=62453&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=62453&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=62453&r=dst IIS Stability: https://bugs.php.net/fix.php?id=62453&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=62453&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=62453&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=62453&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=62453&r=mysqlcfg

« previous php.doc.bugs (#8517) next »