note 20877 deleted from function.crypt by aidan
| From: | aidan@php.net | Date: | Mon, 05 Jul 2004 10:25:08 +0000 |
| Subject: | note 20877 deleted from function.crypt by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-72573@lists.php.net to get a copy of this message | ||
Note Submitter: karl@katzke.net
----
If you're importing DES encrypted passwords from a unix or linux environment, it seems that it
is necessary to use the first to characters as a salt, especially if you're working off of an
old implementation of unix (in my case, DYNIX).
All that aside -- be aware of users that use apostrophes in their passwords. Although they're
rare, they will break php's crypt function -- and I have not found a way around it, except to
use an external function that isn't fazed by apostrophes. MySQL is a great example of this.