Re: PEAR Auth, File_Passwd, and crypt() limitation?
| From: | Ian Eure | Date: | Wed, 13 Apr 2005 21:44:42 +0000 |
| Subject: | Re: PEAR Auth, File_Passwd, and crypt() limitation? | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-37222@lists.php.net to get a copy of this message | ||
On Wednesday 13 April 2005 01:00 pm, Paul M Jones wrote:
> Hi, all,
>
> I've posted a blog entry about using crypt() with passwords longer than
> 8 characters here:
>
> http://paul-m-jones.com/blog/?p=134
>
> I think File_Passwd (and thus indirectly the Cvs.php container for Auth)
> may be susceptible to this as well.
>
> Basically, crypt only checks the first 8 characters, so if the stored
> (crypted) password is "longpassword" and the user enters "longpass" it
> will be treated as a positive check. This is probably bad.
>
> However, I may have missed something that renders my point invalid; I
> leave it to those more learned than I to say. Comments? Criticism?
>
This is a long-known limitation of the original UNIX crypt() implementation.
I think that some sort of warning should be put in the docs (and/or code),
stating the limitations of crypt(). Perhaps a note to the effect that it's
not recommended to use it for anything other than legacy compatibility.
Attachment: [application/pgp-signature]
Attachment: [application/pgp-signature]