Re: PEAR Auth, File_Passwd, and crypt() limitation?

From: Date: Wed, 13 Apr 2005 21:44:42 +0000
Subject: Re: PEAR Auth, File_Passwd, and crypt() limitation?
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-37222@lists.php.net to get a copy of this message
On Wednesday 13 April 2005 01:00 pm, Paul M Jones wrote: > Hi, all, > > I've posted a blog entry about using crypt() with passwords longer than > 8 characters here: > > http://paul-m-jones.com/blog/?p=134 > > I think File_Passwd (and thus indirectly the Cvs.php container for Auth) > may be susceptible to this as well. > > Basically, crypt only checks the first 8 characters, so if the stored > (crypted) password is "longpassword" and the user enters "longpass" it > will be treated as a positive check. This is probably bad. > > However, I may have missed something that renders my point invalid; I > leave it to those more learned than I to say. Comments? Criticism? > This is a long-known limitation of the original UNIX crypt() implementation. I think that some sort of warning should be put in the docs (and/or code), stating the limitations of crypt(). Perhaps a note to the effect that it's not recommended to use it for anything other than legacy compatibility.

Attachment: [application/pgp-signature]
« previous php.pear.dev (#37222) next »