note 38352 deleted from function.crypt by aidan

From: Date: Mon, 05 Jul 2004 10:29:47 +0000
Subject: note 38352 deleted from function.crypt by aidan
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-72598@lists.php.net to get a copy of this message
Note Submitter: François Ropert ---- example of blowfish use under openbsd : You can exploit this script to read /etc/master.passwd lines. $key : Original blowfish hash (salt of crypt function) - Don't replace ' by " because the hash can contains $ character so he will result a bad interpretation. $user_input : character sequence entered by user to calculate blowfish hash with $key. $password : Blowfish hash result of $key and $user_input. <? $key = '$2a$07$A.QAFolLar4v27MGXrrROxpj7hvyhxT2qypSsWtIDjdOSYLMkABq'; $user_input = 'thebestostoserveyou'; $password = crypt($user_input,$key); if ($password == $key) { echo "succesful"; } else { echo "missed"; } Have fun :-)

« previous php.notes (#72598) next »