note 46803 deleted from function.md5 by mazzanet
| From: | mazzanet@php.net | Date: | Mon, 03 Oct 2005 09:26:00 +0000 |
| Subject: | note 46803 deleted from function.md5 by mazzanet | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-96254@lists.php.net to get a copy of this message | ||
Note Submitter: scott at rocketpack dot net
----
In response to "kristian at amazing dot as"
The function provided works well enough if the brute-force is being launched against a record of the
encrypted password.
However, a more likely scenario would involve the brute-force attack taking place against the actual
validation script, in which case the extra security measures would prove useless.
Not only would the latter be easier and less troublesome for the attackers, it would be more
practical.
For that reason I recommend you focus on flood control to limit the ability one has to launch a
brute-force attack.
In response to "simms",
If all you are looking to do is generate a unique filename, simply use uniqid() [13 character
string] or md5( uniqid( '' ) ) [32 character string], or, if you feel like it, md5(
microtime() . rand() ). The methods for creating *truly* unique identifiers are quite numerous.
So, for example, you could do...
<?php
$fileparts = explode( '.', strrev( $origionalName ), 2 );
$finalName = md5( uniqid( '' ) ) . '.' . strrev( $fileparts[0] );
?>
...and rest assured that your files will be safe. =)
In respnose to "mina86 at tlen dot pl" and "Emin Sadykhov
[estof_at_bakinter.net]"
The regexp would actually be:
/^[a-f0-9]{32}$/
As md5() only returns lower case alpha characters. The A-F range is not necessary.
In response to "ASK",
That there is "no such thing as incompatibility between different implementation of MD5"
is almost correct. Due to the fact the different languages manipulate data in different ways, the
exact same methods may not translate directly from one language to another (for example, a language
which uses unsigned integers vs. a language which uses signed integers). However, at the "root
of it all", you are correct- the md5 of two *identitical* entities should be identitical.
That's all =)