note 24212 deleted from function.crypt by jmcastagnetto

From: Date: Fri, 09 Aug 2002 21:37:14 +0000
Subject: note 24212 deleted from function.crypt by jmcastagnetto
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-34634@lists.php.net to get a copy of this message
I am a relatively new user to PHP and this security stuff in general (I never realized how insecure my programs were until I started reading this part of the manual), but when I used the crypt() function, I noticed something really weird. For example, let's say my password is "something1" (without the quotes). If I were to enter my password in and check it against the crypted password in the database, and I enter a password of "something123", I still log in without a problem. As a matter of fact, as long as I know the password and add any characters after it, it checks out. How is this possible?

« previous php.notes (#34634) next »