note 44617 added to ref.mcrypt

From: Date: Wed, 11 Aug 2004 02:16:29 +0000
Subject: note 44617 added to ref.mcrypt
Groups: php.notes 
Request: Send a blank email to php-notes+get-80006@lists.php.net to get a copy of this message
The Algorithm posted by: Mike Zaccari 29-Jun-2004 03:54 Thanks for posting this Mike but there seems to be a problem with your implementation. On my machine and I suspect others, the output is independent of the key. I can change the key and this has no effect on the resulting crypted data. So the input is always encrypted the same way irregardless of the key and therefore decrypted with any key. This would only be secure if an attacker knew nothing about the algorithm which seems unlikely from an experienced attacker. I am looking into a fix and will post if resolved. Does anybody else have this problem? I want to make sure my install is good. I am running on a gentoo linux box. Thanks, Wil Here is the code I am using to test the algorithm: <head><title>Encryption</title> </head> <body> <?php print_debug_header(1); ?> <form name=form method=post action='encrypt.php'> <table align=center> <TR><TD>Source Text:</TD><TD><input type=text name=input value=<?php echo $_REQUEST['input']; ?>></TD></TR> <TR><TD>Key:</TD><TD><input type=text name=key value=<?php echo $_REQUEST['key']; ?>></TD></TR> </table> <input type=submit> </form> <?php if(!empty($_REQUEST['input'])){ $encrypted=encrypt($_REQUEST['input']); $decrypted=decrypt($encrypted); echo "Encrypted : '$encrypted' Decrypted: '$decrypted' <BR>"; } $key = $_REQUEST['key']; //Encrypt Function function encrypt($encrypt) { global $key; $iv = mcrypt_create_iv(mcrypt_get_iv_size(MCRYPT_RIJNDAEL_256, MCRYPT_MODE_ECB), MCRYPT_RAND); $passcrypt = mcrypt_encrypt(MCRYPT_RIJNDAEL_256, $key, $encrypt, MCRYPT_MODE_ECB, $iv); $encode = base64_encode($passcrypt); return $encode; } //Decrypt Function function decrypt($decrypt) { global $key; $decoded = base64_decode($decrypt); $iv = mcrypt_create_iv(mcrypt_get_iv_size(MCRYPT_RIJNDAEL_256, MCRYPT_MODE_ECB), MCRYPT_RAND); $decrypted = mcrypt_decrypt(MCRYPT_RIJNDAEL_256, $key, $decoded, MCRYPT_MODE_ECB, $iv); return $decrypted; } ?> </body> </html> ---- Manual Page -- http://www.php.net/manual/en/ref.mcrypt.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+44617 Delete -- http://master.php.net/manage/user-notes.php?action=delete+44617&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+44617&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#80006) next »