note 27790 deleted from function.uniqid by didou
| From: | didou@php.net | Date: | Tue, 19 Aug 2003 14:10:11 +0000 |
| Subject: | note 27790 deleted from function.uniqid by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-54676@lists.php.net to get a copy of this message | ||
Note Submitter: /r/q/u/i/n/n at /w/e/b /d/e
----
Editor: This is a good example for how NOT to do it. Your only entropy comes from microtime() here
which is an extremely WEAK entropy source. md5(uniqid("", 1)) is way better, because it
uses hard to predict entropy. So, don't follow the example below.
----------------------------------------------------------
My way of generating an ID (32 char string) for use as session identifiers. Just call
NewSessionIdentifier() and use the return value as you like.
//srand just once please
srand((double)microtime()*1000000);
//return a (pseudo) random string of specified length, default=114
function RandomString( $passwordLength=114) {
$password = "";
for ($index = 1; $index <= $passwordLength; $index++) {
// Pick random number between 1 and 62
$randomNumber = rand(1, 62);
// Select random character based on mapping.
if ($randomNumber < 11)
$password .= Chr($randomNumber + 48 - 1); // [ 1,10] => [0,9]
else if ($randomNumber < 37)
$password .= Chr($randomNumber + 65 - 10); // [11,36] => [A,Z]
else
$password .= Chr($randomNumber + 97 - 36); // [37,62] => [a,z]
}
return $password;
}
//Returns randomness as string
function NewSessionIdentifier()
{
//MD5 it (always 32 bytes long)
return (string) md5(uniqid (RandomString(114),1 ));
}