PEAR Auth, File_Passwd, and crypt() limitation?
| From: | Paul M Jones | Date: | Wed, 13 Apr 2005 20:00:10 +0000 |
| Subject: | PEAR Auth, File_Passwd, and crypt() limitation? | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-37217@lists.php.net to get a copy of this message | ||
Hi, all,
I've posted a blog entry about using crypt() with passwords longer than 8 characters here:
http://paul-m-jones.com/blog/?p=134I think File_Passwd (and thus indirectly the Cvs.php container for Auth) may be susceptible to this as well. Basically, crypt only checks the first 8 characters, so if the stored (crypted) password is "longpassword" and the user enters "longpass" it will be treated as a positive check. This is probably bad. However, I may have missed something that renders my point invalid; I leave it to those more learned than I to say. Comments? Criticism? -- pmj