Doc #62453 [Com]: Terrible sample code
| From: | nikic@php.net | Date: | Sat, 30 Jun 2012 11:14:01 +0000 |
| Subject: | Doc #62453 [Com]: Terrible sample code | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-8520@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=62453&edit=1
ID: 62453
Comment by: nikic@php.net
Reported by: maarten dot bodewes at gmail dot com
Summary: Terrible sample code
Status: Open
Type: Documentation Problem
Package: Documentation problem
PHP Version: 5.4.4
Block user comment: N
Private report: N
New Comment:
Could you maybe provide a better example for the function? I don't know anything about the
topic at hand, so I probably can't come up with a good example on my own.
Previous Comments:
------------------------------------------------------------------------
[2012-06-29 23:49:49] maarten dot bodewes at gmail dot com
Description:
------------
---
From manual page: http://www.php.net/function.mcrypt-encrypt#refsect1-function.mcrypt-encrypt-examples
---
Hi, I'm a security professional (+10 years experience). I'm wondering which arse wrote
that PHP sample this bug is pointing at. The following mistakes are present (at the minimum):
* using an IV with ECB encoding
* using ECB at all for non random plain text
* using ECB within an example in the first place
* mistaking a passphrase with a key (keys should be random bytes of data, or at least generated
using e.g. PBKDF2, bcrypt or scrypt)
* supplying an incorrect number of characters for the key (25 if I'm not mistaken)
* using MCRYPT_RIJNDAEL_256 instead of MCRYPT_RIJNDAEL_128 (AES)
* not performing PKCS#7 padding by default
If this sample is to coax unsuspecting people in writing insecure code which is not compatible with
any crypto library out there, keep it in. Otherwise toss it out and start over again.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=62453&edit=1