note 23433 added to function.crypt

From: Date: Thu, 18 Jul 2002 13:00:27 +0000
Subject: note 23433 added to function.crypt
Groups: php.notes 
Request: Send a blank email to php-notes+get-33248@lists.php.net to get a copy of this message
Just a point I noticed when trying to handle crypted password-comparison. I first created a password using a simple crypt("gadget"); call, which created the following password: $1$rFyQGXan$FGx6ggXNaz/NW912zs but then, when I come to comparing it with the user's entry, I use the password generated in the Database (with a random salt since I didn't specify one) to specify the salt for crypting the user's password entry. In other words, $db_passwd is the crypted password you've just seen, and $passwd is what the user enters: "gadget"; which is exactly the original password before encryption. Well, when doing a $passwd=crypt($passwd,$db_passwd); , it give the following result: $1$rFyQGXan$FGx6ggXNaz/NW912zs269/ which is exactly the same crypting as the one in the database, except the '269/' chars at the end. Don't ask me why, but crypt() seems to be adding chars when specifying the key ? anyway, I guess that just removing those 4 extra chars in the comparison does the trick, but i find it weird anyway. -- http://www.php.net/manual/en/function.crypt.php http://master.php.net/manage/user-notes.php?action=edit+23433 http://master.php.net/manage/user-notes.php?action=delete+23433 http://master.php.net/manage/user-notes.php?action=reject+23433

« previous php.notes (#33248) next »