note 47724 added to function.crypt

From: Date: Fri, 26 Nov 2004 16:21:45 +0000
Subject: note 47724 added to function.crypt
Groups: php.notes 
Request: Send a blank email to php-notes+get-81066@lists.php.net to get a copy of this message
There appears to be a limitation with this function, where it only validates upto a characters, therefore the 9th character onwards can be ommitted, which limits useful passwords to 8 characters only. Example <?php $password = "qwertyuiopasdfghjkl"; // Encrypt the password, but let's use a known MD5 hash as the salt $salt = ""0f2d92cee71e5f93f3abecdc666a6b7d"; $salt = substr($salt, 0, CRYPT_SALT_LENGTH ); $encrypted = crypt($password, $salt); // Now do the comparison $shortPass = substr($password, 0, 8); if (crypt( $shortPass, $encrypted ) == $encrypted ) echo "The passwords match"; else echo "The passwords do not match"; ?> This will print: "The passwords match" even though $shortPass is "qwertyui" and $password is "qwertyuiopasdfghjkl" ---- Manual Page -- http://www.php.net/manual/en/function.crypt.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+47724 Delete -- http://master.php.net/manage/user-notes.php?action=delete+47724&report=yes Reason: bad code -- http://master.php.net/manage/user-notes.php?action=delete+47724&report=yes&reason=bad+code Reason: spam -- http://master.php.net/manage/user-notes.php?action=delete+47724&report=yes&reason=spam Reason: useless example -- http://master.php.net/manage/user-notes.php?action=delete+47724&report=yes&reason=useless+example Reason: contains commercial links -- http://master.php.net/manage/user-notes.php?action=delete+47724&report=yes&reason=contains+commercial+links Reason: useless note -- http://master.php.net/manage/user-notes.php?action=delete+47724&report=yes&reason=useless+note Reject -- http://master.php.net/manage/user-notes.php?action=reject+47724&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#81066) next »