note 40397 modified in ref.mcrypt by cece

From: Date: Wed, 03 Nov 2004 02:09:41 +0000
Subject: note 40397 modified in ref.mcrypt by cece
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-79524@lists.php.net to get a copy of this message
15-Feb-2004 06:17 "I found this nested loop very useful for checking the sanity of my libmcrypt install. It turned out many of the modules weren't working in certain modes. Hopefully this will save someone some frustration:" I have ammended the mcrypt_check_sanity() function. This is a bug fix: the function was reinitializing the IV, which is unacceptable. Here is the complete, fixed version. Note that 'stream' mode is not tested. <?PHP /* run a self-test through every listed cipher and mode */ function mcrypt_check_sanity() { $modes = mcrypt_list_modes(); $algorithms = mcrypt_list_algorithms(); foreach ($algorithms as $cipher) { if(mcrypt_module_self_test($cipher)) { print $cipher." ok.<br />\n"; } else { print $cipher." not ok.<br />\n"; } foreach ($modes as $mode) { if($mode == 'stream') { $result = "not tested"; } else if(mcrypt_test_module_mode($cipher,$mode)) { $result = "ok"; } else { $result = "not ok"; } print $cipher." in mode ".$mode." ".$result."<br />\n"; mcrypt_module_close($td); } } } // a variant on the example posted in mdecrypt_generic function mcrypt_test_module_mode($module,$mode) { /* Data */ $key = 'this is a very long key, even too long for the cipher'; $plain_text = 'very important data'; /* Open module, and create IV */ $td = mcrypt_module_open($module, '',$mode, ''); $key = substr($key, 0, mcrypt_enc_get_key_size($td)); $iv_size = mcrypt_enc_get_iv_size($td); $iv = mcrypt_create_iv($iv_size, MCRYPT_RAND); /* Initialize encryption handle */ if (mcrypt_generic_init($td, $key, $iv) != -1) { /* Encrypt data */ $c_t = mcrypt_generic($td, $plain_text); mcrypt_generic_deinit($td); // close the module mcrypt_module_close($td); /* Reinitialize buffers for decryption */ /* Open module */ $td = mcrypt_module_open($module, '', $mode, ''); $key = substr($key, 0, mcrypt_enc_get_key_size($td)); mcrypt_generic_init($td, $key, $iv); $p_t = trim(mdecrypt_generic($td, $c_t)); //trim to remove padding /* Clean up */ mcrypt_generic_end($td); mcrypt_module_close($td); } if (strncmp($p_t, $plain_text, strlen($plain_text)) == 0) { return TRUE; } else { return FALSE; } } // function call: mcrypt_check_sanity(); ?> Apologies for any confusion the previous version may have caused. The only working mode listed was ecb, since it does not use an IV. --was-- I have ammended the mcrypt_check_sanity() function. This is a bug fix: the function was reinitializing the IV, which is unacceptable. Here is the complete, fixed version. Note that 'stream' mode is not tested. <?PHP /* run a self-test through every listed cipher and mode */ function mcrypt_check_sanity() { $modes = mcrypt_list_modes(); $algorithms = mcrypt_list_algorithms(); foreach ($algorithms as $cipher) { if(mcrypt_module_self_test($cipher)) { print $cipher." ok.<br />\n"; } else { print $cipher." not ok.<br />\n"; } foreach ($modes as $mode) { if($mode == 'stream') { $result = "not tested"; } else if(mcrypt_test_module_mode($cipher,$mode)) { $result = "ok"; } else { $result = "not ok"; } print $cipher." in mode ".$mode." ".$result."<br />\n"; mcrypt_module_close($td); } } } // a variant on the example posted in mdecrypt_generic function mcrypt_test_module_mode($module,$mode) { /* Data */ $key = 'this is a very long key, even too long for the cipher'; $plain_text = 'very important data'; /* Open module, and create IV */ $td = mcrypt_module_open($module, '',$mode, ''); $key = substr($key, 0, mcrypt_enc_get_key_size($td)); $iv_size = mcrypt_enc_get_iv_size($td); $iv = mcrypt_create_iv($iv_size, MCRYPT_RAND); /* Initialize encryption handle */ if (mcrypt_generic_init($td, $key, $iv) != -1) { /* Encrypt data */ $c_t = mcrypt_generic($td, $plain_text); mcrypt_generic_deinit($td); // close the module mcrypt_module_close($td); /* Reinitialize buffers for decryption */ /* Open module */ $td = mcrypt_module_open($module, '', $mode, ''); $key = substr($key, 0, mcrypt_enc_get_key_size($td)); mcrypt_generic_init($td, $key, $iv); $p_t = trim(mdecrypt_generic($td, $c_t)); //trim to remove padding /* Clean up */ mcrypt_generic_end($td); mcrypt_module_close($td); } if (strncmp($p_t, $plain_text, strlen($plain_text)) == 0) { return TRUE; } else { return FALSE; } } // function call: mcrypt_check_sanity(); ?> Apologies for any confusion the previous version may have caused. The only working mode listed was ecb, since it does not use an IV. http://php.net/manual/en/ref.mcrypt.php

« previous php.notes (#79524) next »