note 24212 added to function.crypt
| From: | linczak dot 1 at osu dot edu | Date: | Fri, 09 Aug 2002 14:54:59 +0000 |
| Subject: | note 24212 added to function.crypt | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-34610@lists.php.net to get a copy of this message | ||
I am a relatively new user to PHP and this security stuff in general (I never realized how insecure
my programs were until I started reading this part of the manual), but when I used the crypt()
function, I noticed something really weird. For example, let's say my password is
"something1" (without the quotes). If I were to enter my password in and check it against
the crypted password in the database, and I enter a password of "something123", I still
log in without a problem. As a matter of fact, as long as I know the password and add any
characters after it, it checks out. How is this possible?
--
http://www.php.net/manual/en/function.crypt.php
http://master.php.net/manage/user-notes.php?action=edit+24212
http://master.php.net/manage/user-notes.php?action=delete+24212
http://master.php.net/manage/user-notes.php?action=reject+24212