note 23433 deleted from function.crypt by jmcastagnetto
| From: | jmcastagnetto@php.net | Date: | Sun, 29 Dec 2002 07:54:38 +0000 |
| Subject: | note 23433 deleted from function.crypt by jmcastagnetto | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-41413@lists.php.net to get a copy of this message | ||
Just a point I noticed when trying to handle crypted password-comparison. I first created a password
using a simple crypt("gadget"); call, which created the following password:
$1$rFyQGXan$FGx6ggXNaz/NW912zs
but then, when I come to comparing it with the user's entry, I use the password generated in
the Database (with a random salt since I didn't specify one) to specify the salt for crypting
the user's password entry. In other words, $db_passwd is the crypted password you've just
seen, and $passwd is what the user enters: "gadget"; which is exactly the original
password before encryption. Well, when doing a $passwd=crypt($passwd,$db_passwd); , it give the
following result:
$1$rFyQGXan$FGx6ggXNaz/NW912zs269/
which is exactly the same crypting as the one in the database, except the '269/' chars at
the end. Don't ask me why, but crypt() seems to be adding chars when specifying the key ?
anyway, I guess that just removing those 4 extra chars in the comparison does the trick, but i find
it weird anyway.