note 44617 deleted from ref.mcrypt by danbrown

From: Date: Mon, 13 Dec 2010 16:27:38 +0000
Subject: note 44617 deleted from ref.mcrypt by danbrown
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-174873@lists.php.net to get a copy of this message
Note Submitter: Wilmo ---- The Algorithm posted by: Mike Zaccari 29-Jun-2004 03:54 "I'm running PHP 4.3.7 on Apache 2.0.49 on an Xp machine, and after many hours of googling over the internet I found that the easiest way to use the mcrypt function was to do this:" Thanks for posting this Mike but there seems to be a problem with your implementation. On my machine and I suspect others, the output is independent of the key. I can change the key and this has no effect on the resulting crypted data. So the input is always encrypted the same way irregardless of the key and therefore decrypted with any key. This would only be secure if an attacker knew nothing about the algorithm which seems unlikely from an experienced attacker. I am looking into a fix and will post if resolved. Does anybody else have this problem? I want to make sure my install is good. I am running on a gentoo linux box. Thanks, Wil Here is the code I am using to test the algorithm: <head><title>Encryption</title> </head> <body> <?php print_debug_header(1); ?> <form name=form method=post action='encrypt.php'> <table align=center> <TR><TD>Source Text:</TD><TD><input type=text name=input value=<?php echo $_REQUEST['input']; ?>></TD></TR> <TR><TD>Key:</TD><TD><input type=text name=key value=<?php echo $_REQUEST['key']; ?>></TD></TR> </table> <input type=submit> </form> <?php if(!empty($_REQUEST['input'])){ $encrypted=encrypt($_REQUEST['input']); $decrypted=decrypt($encrypted); echo "Encrypted : '$encrypted' Decrypted: '$decrypted' <BR>"; } $key = $_REQUEST['key']; //Encrypt Function function encrypt($encrypt) { global $key; $iv = mcrypt_create_iv(mcrypt_get_iv_size(MCRYPT_RIJNDAEL_256, MCRYPT_MODE_ECB), MCRYPT_RAND); $passcrypt = mcrypt_encrypt(MCRYPT_RIJNDAEL_256, $key, $encrypt, MCRYPT_MODE_ECB, $iv); $encode = base64_encode($passcrypt); return $encode; } //Decrypt Function function decrypt($decrypt) { global $key; $decoded = base64_decode($decrypt); $iv = mcrypt_create_iv(mcrypt_get_iv_size(MCRYPT_RIJNDAEL_256, MCRYPT_MODE_ECB), MCRYPT_RAND); $decrypted = mcrypt_decrypt(MCRYPT_RIJNDAEL_256, $key, $decoded, MCRYPT_MODE_ECB, $iv); return $decrypted; } ?> </body> </html>

« previous php.notes (#174873) next »