note 47724 deleted from function.crypt by joey

From: Date: Mon, 27 Dec 2010 12:20:48 +0000
Subject: note 47724 deleted from function.crypt by joey
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-175232@lists.php.net to get a copy of this message
Note Submitter: antony at anonymous dot anon dot com ---- There appears to be a limitation with this function, where it only validates upto a characters, therefore the 9th character onwards can be ommitted, which limits useful passwords to 8 characters only. Example <?php $password = "qwertyuiopasdfghjkl"; // Encrypt the password, but let's use a known MD5 hash as the salt $salt = ""0f2d92cee71e5f93f3abecdc666a6b7d"; $salt = substr($salt, 0, CRYPT_SALT_LENGTH ); $encrypted = crypt($password, $salt); // Now do the comparison $shortPass = substr($password, 0, 8); if (crypt( $shortPass, $encrypted ) == $encrypted ) echo "The passwords match"; else echo "The passwords do not match"; ?> This will print: "The passwords match" even though $shortPass is "qwertyui" and $password is "qwertyuiopasdfghjkl"

« previous php.notes (#175232) next »