note 23433 deleted from function.crypt by jmcastagnetto

From: Date: Sun, 29 Dec 2002 07:54:38 +0000
Subject: note 23433 deleted from function.crypt by jmcastagnetto
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-41413@lists.php.net to get a copy of this message
Just a point I noticed when trying to handle crypted password-comparison. I first created a password using a simple crypt("gadget"); call, which created the following password: $1$rFyQGXan$FGx6ggXNaz/NW912zs but then, when I come to comparing it with the user's entry, I use the password generated in the Database (with a random salt since I didn't specify one) to specify the salt for crypting the user's password entry. In other words, $db_passwd is the crypted password you've just seen, and $passwd is what the user enters: "gadget"; which is exactly the original password before encryption. Well, when doing a $passwd=crypt($passwd,$db_passwd); , it give the following result: $1$rFyQGXan$FGx6ggXNaz/NW912zs269/ which is exactly the same crypting as the one in the database, except the '269/' chars at the end. Don't ask me why, but crypt() seems to be adding chars when specifying the key ? anyway, I guess that just removing those 4 extra chars in the comparison does the trick, but i find it weird anyway.

« previous php.notes (#41413) next »