note 23433 added to function.crypt
| From: | manfire at softhome dot net | Date: | Thu, 18 Jul 2002 13:00:27 +0000 |
| Subject: | note 23433 added to function.crypt | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-33248@lists.php.net to get a copy of this message | ||
Just a point I noticed when trying to handle crypted password-comparison. I first created a password
using a simple crypt("gadget"); call, which created the following password:
$1$rFyQGXan$FGx6ggXNaz/NW912zs
but then, when I come to comparing it with the user's entry, I use the password generated in
the Database (with a random salt since I didn't specify one) to specify the salt for crypting
the user's password entry. In other words, $db_passwd is the crypted password you've just
seen, and $passwd is what the user enters: "gadget"; which is exactly the original
password before encryption. Well, when doing a $passwd=crypt($passwd,$db_passwd); , it give the
following result:
$1$rFyQGXan$FGx6ggXNaz/NW912zs269/
which is exactly the same crypting as the one in the database, except the '269/' chars at
the end. Don't ask me why, but crypt() seems to be adding chars when specifying the key ?
anyway, I guess that just removing those 4 extra chars in the comparison does the trick, but i find
it weird anyway.
--
http://www.php.net/manual/en/function.crypt.php
http://master.php.net/manage/user-notes.php?action=edit+23433
http://master.php.net/manage/user-notes.php?action=delete+23433
http://master.php.net/manage/user-notes.php?action=reject+23433