note 27790 deleted from function.uniqid by didou

From: Date: Tue, 19 Aug 2003 14:10:11 +0000
Subject: note 27790 deleted from function.uniqid by didou
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-54676@lists.php.net to get a copy of this message
Note Submitter: /r/q/u/i/n/n at /w/e/b /d/e ---- Editor: This is a good example for how NOT to do it. Your only entropy comes from microtime() here which is an extremely WEAK entropy source. md5(uniqid("", 1)) is way better, because it uses hard to predict entropy. So, don't follow the example below. ---------------------------------------------------------- My way of generating an ID (32 char string) for use as session identifiers. Just call NewSessionIdentifier() and use the return value as you like. //srand just once please srand((double)microtime()*1000000); //return a (pseudo) random string of specified length, default=114 function RandomString( $passwordLength=114) { $password = ""; for ($index = 1; $index <= $passwordLength; $index++) { // Pick random number between 1 and 62 $randomNumber = rand(1, 62); // Select random character based on mapping. if ($randomNumber < 11) $password .= Chr($randomNumber + 48 - 1); // [ 1,10] => [0,9] else if ($randomNumber < 37) $password .= Chr($randomNumber + 65 - 10); // [11,36] => [A,Z] else $password .= Chr($randomNumber + 97 - 36); // [37,62] => [a,z] } return $password; } //Returns randomness as string function NewSessionIdentifier() { //MD5 it (always 32 bytes long) return (string) md5(uniqid (RandomString(114),1 )); }

« previous php.notes (#54676) next »