note 24212 deleted from function.crypt by jmcastagnetto
| From: | jmcastagnetto@php.net | Date: | Fri, 09 Aug 2002 21:37:14 +0000 |
| Subject: | note 24212 deleted from function.crypt by jmcastagnetto | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-34634@lists.php.net to get a copy of this message | ||
I am a relatively new user to PHP and this security stuff in general (I never realized how insecure
my programs were until I started reading this part of the manual), but when I used the crypt()
function, I noticed something really weird. For example, let's say my password is
"something1" (without the quotes). If I were to enter my password in and check it against
the crypted password in the database, and I enter a password of "something123", I still
log in without a problem. As a matter of fact, as long as I know the password and add any
characters after it, it checks out. How is this possible?