Doc #64041 [Opn->Dup]: Example shows unsafe use of encryption

From: Date: Fri, 07 Jun 2013 20:04:00 +0000
Subject: Doc #64041 [Opn->Dup]: Example shows unsafe use of encryption
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-9907@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=64041&edit=1 ID: 64041 Updated by: nikic@php.net Reported by: pawel dot krawczyk at hush dot com Summary: Example shows unsafe use of encryption -Status: Open +Status: Duplicate Type: Documentation Problem Package: Documentation problem Operating System: n/a PHP Version: Irrelevant Block user comment: N Private report: N New Comment: Has been fixed, see duplicate bug: https://bugs.php.net/bug.php?id=62453 Previous Comments: ------------------------------------------------------------------------ [2013-01-21 20:48:28] pawel dot krawczyk at hush dot com Description: ------------ --- From manual page: http://www.php.net/function.mcrypt-encrypt#refsect1- function.mcrypt-encrypt-examples --- The mcrypt_encrypt() example shows simple encryption using ECB mode and with no message integrity validation. This is then being copied by people in production applications, creating vulnerabilies. It would help a lot if the example also added HMAC calculation for the message. Its validation should be added to mcrypt_decrypt() function. http://php.net/manual/en/function.hash-hmac.php ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=64041&edit=1

« previous php.doc.bugs (#9907) next »