note 40397 added to ref.mcrypt

From: Date: Tue, 02 Mar 2004 19:59:38 +0000
Subject: note 40397 added to ref.mcrypt
Groups: php.notes 
Request: Send a blank email to php-notes+get-66127@lists.php.net to get a copy of this message
I have ammended the mcrypt_check_sanity() function. This is a bug fix: the function was reinitializing the IV, which is unacceptable. Here is the complete, fixed version. Note that 'stream' mode is not tested. <?PHP /* run a self-test through every listed cipher and mode */ function mcrypt_check_sanity() { $modes = mcrypt_list_modes(); $algorithms = mcrypt_list_algorithms(); foreach ($algorithms as $cipher) { if(mcrypt_module_self_test($cipher)) { print $cipher." ok.<br />\n"; } else { print $cipher." not ok.<br />\n"; } foreach ($modes as $mode) { if($mode == 'stream') { $result = "not tested"; } else if(mcrypt_test_module_mode($cipher,$mode)) { $result = "ok"; } else { $result = "not ok"; } print $cipher." in mode ".$mode." ".$result."<br />\n"; mcrypt_module_close($td); } } } // a variant on the example posted in mdecrypt_generic function mcrypt_test_module_mode($module,$mode) { /* Data */ $key = 'this is a very long key, even too long for the cipher'; $plain_text = 'very important data'; /* Open module, and create IV */ $td = mcrypt_module_open($module, '',$mode, ''); $key = substr($key, 0, mcrypt_enc_get_key_size($td)); $iv_size = mcrypt_enc_get_iv_size($td); $iv = mcrypt_create_iv($iv_size, MCRYPT_RAND); /* Initialize encryption handle */ if (mcrypt_generic_init($td, $key, $iv) != -1) { /* Encrypt data */ $c_t = mcrypt_generic($td, $plain_text); mcrypt_generic_deinit($td); // close the module mcrypt_module_close($td); /* Reinitialize buffers for decryption */ /* Open module */ $td = mcrypt_module_open($module, '', $mode, ''); $key = substr($key, 0, mcrypt_enc_get_key_size($td)); mcrypt_generic_init($td, $key, $iv); $p_t = trim(mdecrypt_generic($td, $c_t)); //trim to remove padding /* Clean up */ mcrypt_generic_end($td); mcrypt_module_close($td); } if (strncmp($p_t, $plain_text, strlen($plain_text)) == 0) { return TRUE; } else { return FALSE; } } // function call: mcrypt_check_sanity(); ?> Apologies for any confusion the previous version may have caused. The only working mode listed was ecb, since it does not use an IV. ---- Manual Page -- http://www.php.net/manual/en/ref.mcrypt.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+40397 Delete -- http://master.php.net/manage/user-notes.php?action=delete+40397&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+40397&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#66127) next »