note 46803 added to function.md5

From: Date: Sun, 24 Oct 2004 07:28:38 +0000
Subject: note 46803 added to function.md5
Groups: php.notes 
Request: Send a blank email to php-notes+get-79011@lists.php.net to get a copy of this message
In response to "kristian at amazing dot as" The function provided works well enough if the brute-force is being launched against a record of the encrypted password. However, a more likely scenario would involve the brute-force attack taking place against the actual validation script, in which case the extra security measures would prove useless. Not only would the latter be easier and less troublesome for the attackers, it would be more practical. For that reason I recommend you focus on flood control to limit the ability one has to launch a brute-force attack. In response to "simms", If all you are looking to do is generate a unique filename, simply use uniqid() [13 character string] or md5( uniqid( '' ) ) [32 character string], or, if you feel like it, md5( microtime() . rand() ). The methods for creating *truly* unique identifiers are quite numerous. So, for example, you could do... <?php $fileparts = explode( '.', strrev( $origionalName ), 2 ); $finalName = md5( uniqid( '' ) ) . '.' . strrev( $fileparts[0] ); ?> ...and rest assured that your files will be safe. =) In respnose to "mina86 at tlen dot pl" and "Emin Sadykhov [estof_at_bakinter.net]" The regexp would actually be: /^[a-f0-9]{32}$/ As md5() only returns lower case alpha characters. The A-F range is not necessary. In response to "ASK", That there is "no such thing as incompatibility between different implementation of MD5" is almost correct. Due to the fact the different languages manipulate data in different ways, the exact same methods may not translate directly from one language to another (for example, a language which uses unsigned integers vs. a language which uses signed integers). However, at the "root of it all", you are correct- the md5 of two *identitical* entities should be identitical. That's all =) ---- Manual Page -- http://www.php.net/manual/en/function.md5.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+46803 Delete -- http://master.php.net/manage/user-notes.php?action=delete+46803&report=yes Reason: bad code -- http://master.php.net/manage/user-notes.php?action=delete+46803&report=yes&reason=bad+code Reason: spam -- http://master.php.net/manage/user-notes.php?action=delete+46803&report=yes&reason=spam Reason: useless example -- http://master.php.net/manage/user-notes.php?action=delete+46803&report=yes&reason=useless+example Reason: contains commercial links -- http://master.php.net/manage/user-notes.php?action=delete+46803&report=yes&reason=contains+commercial+links Reason: useless note -- http://master.php.net/manage/user-notes.php?action=delete+46803&report=yes&reason=useless+note Reject -- http://master.php.net/manage/user-notes.php?action=reject+46803&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#79011) next »