11 ms·
Get ready for some WTF-ery Crypt takes an optional salt. If that value is an MD5 hash it is prefixed with the chars $1$ to tell the underlying crypt(3) function
by dramaticus3 15y ago
Get ready for some WTF-ery
Crypt takes an optional salt.
If that value is an MD5 hash it is prefixed with the chars $1$ to tell the underlying crypt(3) function to use Modular Crypt Format[1].
MCF is an ad-hoc cruft because the orginal crypt() is weak.
Anyway guess who did it :
"let's use strlcpy/strlcat instead for these static string copies" - Rasmus
I guess that's Lerdorf himself
Whoever it was also didn't check the return values for error. Strlcat returns the length of the new string which might not be the same as strlen(dst) + strlen(src).
"I'm not a real programmer. I throw together things until it works then I move on." - Rasmus Lerdorf
Here's where he broke it : Sun Aug 7 16:10:34 2011 UTC
http://svn.php.net/viewvc/php/php-src/trunk/ext/standard/php_crypt_r.c?sortdir=down&r1=313615&r2=314434&sortby=date http://svn.php.net/viewvc/php/php-src/trunk/ext/standard/php...
Here's it being fixed : Fri Aug 19 22:49:18 2011 UTC
http://svn.php.net/viewvc/php/php-src/trunk/ext/standard/php_crypt_r.c?sortdir=down&r1=314438&r2=315218&sortby=date http://svn.php.net/viewvc/php/php-src/trunk/ext/standard/php...
[1] http://packages.python.org/passlib/modular_crypt_format.html http://packages.python.org/passlib/modular_crypt_format.html
- rll 15y agoIf you have never broken anything you have probably never built anything.
- dramaticus3 15y agoThe project leader. Tests, I'm in charge, I don't test.
- dangrossman 15y agoThis code had a unit test, and it failed after the change as expected: http://gcov.php.net/viewer.php?version=PHP_5_3&func=tests&file=ext%2Fstandard%2Ftests%2Fstrings%2Fcrypt.phpt http://gcov.php.net/viewer.php?version=PHP_5_3&func=test...