note 38352 deleted from function.crypt by aidan
| From: | aidan@php.net | Date: | Mon, 05 Jul 2004 10:29:47 +0000 |
| Subject: | note 38352 deleted from function.crypt by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-72598@lists.php.net to get a copy of this message | ||
Note Submitter: François Ropert
----
example of blowfish use under openbsd :
You can exploit this script to read /etc/master.passwd lines.
$key : Original blowfish hash (salt of crypt function) - Don't replace ' by " because
the hash can contains $ character so he will result a bad interpretation.
$user_input : character sequence entered by user to calculate blowfish hash with $key.
$password : Blowfish hash result of $key and $user_input.
<?
$key = '$2a$07$A.QAFolLar4v27MGXrrROxpj7hvyhxT2qypSsWtIDjdOSYLMkABq';
$user_input = 'thebestostoserveyou';
$password = crypt($user_input,$key);
if ($password == $key) {
echo "succesful";
}
else
{
echo "missed";
}
Have fun :-)