4 ms·
As @TimWolla commented somewhere else: https://stackoverflow.com/questions/75519073/password-verify-works-in-php-7-4-but-doesnt-work-in-php-8-2 https://stackove
by pytness 4y ago
As @TimWolla commented somewhere else:
https://stackoverflow.com/questions/75519073/password-verify-works-in-php-7-4-but-doesnt-work-in-php-8-2 https://stackoverflow.com/questions/75519073/password-verify...
- TimWolla 4y agoNote: The hash in the SO question is not vulnerable, because it is too long. The issue exists specifically for hashes that both contain a `$` and are too short. The “too short” is necessary for the trailing NUL byte of the input to be copied into the output and thus to truncate early because of the `strlen()`.