note 690 deleted from function.crypt by nlopess
| From: | nlopess@php.net | Date: | Sat, 03 Jan 2004 16:37:10 +0000 |
| Subject: | note 690 deleted from function.crypt by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-62865@lists.php.net to get a copy of this message | ||
Note Submitter: webmaster@l-i-e.com
----
crypt() on operating systems where multiple encryption mechanisms are supported gets triggered by
the actual salt you feed it. If you feed crypt a 2-char salt, then it will use DES encryption. If
you feed it a 12-char salt starting with $1$ it will use MD5. If you feed it a 17-char salt
starting with $2$ it will do Blowfish.
<p>
It has been theorized that feeding salt for an encryption method that is not supported by the OS
will result in some other encryption being employed. If true, it might be possible to detect
unsupported encryption methods by providing a salt and comparing the first n characters of the
result with the provided salt.