note 24212 added to function.crypt

From: Date: Fri, 09 Aug 2002 14:54:59 +0000
Subject: note 24212 added to function.crypt
Groups: php.notes 
Request: Send a blank email to php-notes+get-34610@lists.php.net to get a copy of this message
I am a relatively new user to PHP and this security stuff in general (I never realized how insecure my programs were until I started reading this part of the manual), but when I used the crypt() function, I noticed something really weird. For example, let's say my password is "something1" (without the quotes). If I were to enter my password in and check it against the crypted password in the database, and I enter a password of "something123", I still log in without a problem. As a matter of fact, as long as I know the password and add any characters after it, it checks out. How is this possible? -- http://www.php.net/manual/en/function.crypt.php http://master.php.net/manage/user-notes.php?action=edit+24212 http://master.php.net/manage/user-notes.php?action=delete+24212 http://master.php.net/manage/user-notes.php?action=reject+24212

« previous php.notes (#34610) next »