note 44743 added to function.crypt

From: Date: Sun, 15 Aug 2004 02:58:51 +0000
Subject: note 44743 added to function.crypt
Groups: php.notes 
Request: Send a blank email to php-notes+get-74679@lists.php.net to get a copy of this message
The crypt-function only takes the 8 first character into consideration when creating the output. For example crypt("aaaaaaaa222","aa");outputs the same as crypt("aaaaaaaa111","aa"); Could be fatal if you e.g use crypt($hostname + $username,"aa") as validation to your website. md5 would do good, but creates a 32 character string, that doesn't look good in the addressbar. My suggested solution: $crypted_long_string = crypt(md5($long_string),"aa"); ---- Manual Page -- http://www.php.net/manual/en/function.crypt.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+44743 Delete -- http://master.php.net/manage/user-notes.php?action=delete+44743&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+44743&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#74679) next »