note 46803 deleted from function.md5 by mazzanet

From: Date: Mon, 03 Oct 2005 09:26:00 +0000
Subject: note 46803 deleted from function.md5 by mazzanet
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-96254@lists.php.net to get a copy of this message
Note Submitter: scott at rocketpack dot net ---- In response to "kristian at amazing dot as" The function provided works well enough if the brute-force is being launched against a record of the encrypted password. However, a more likely scenario would involve the brute-force attack taking place against the actual validation script, in which case the extra security measures would prove useless. Not only would the latter be easier and less troublesome for the attackers, it would be more practical. For that reason I recommend you focus on flood control to limit the ability one has to launch a brute-force attack. In response to "simms", If all you are looking to do is generate a unique filename, simply use uniqid() [13 character string] or md5( uniqid( '' ) ) [32 character string], or, if you feel like it, md5( microtime() . rand() ). The methods for creating *truly* unique identifiers are quite numerous. So, for example, you could do... <?php $fileparts = explode( '.', strrev( $origionalName ), 2 ); $finalName = md5( uniqid( '' ) ) . '.' . strrev( $fileparts[0] ); ?> ...and rest assured that your files will be safe. =) In respnose to "mina86 at tlen dot pl" and "Emin Sadykhov [estof_at_bakinter.net]" The regexp would actually be: /^[a-f0-9]{32}$/ As md5() only returns lower case alpha characters. The A-F range is not necessary. In response to "ASK", That there is "no such thing as incompatibility between different implementation of MD5" is almost correct. Due to the fact the different languages manipulate data in different ways, the exact same methods may not translate directly from one language to another (for example, a language which uses unsigned integers vs. a language which uses signed integers). However, at the "root of it all", you are correct- the md5 of two *identitical* entities should be identitical. That's all =)

« previous php.notes (#96254) next »