password_verify() failed to verify bcrypt passwords containing null bytes
未关闭
还没有人认领这个 Issue。
Bug
Extension: standard
Status: Needs Triage
- 主要语言
- C
- 星标
- 40.4k
- 派生
- 8.1k
- 平均合并
- 2 天 13 小时
- 30 天内合并 PR
- 96
描述
Description
The following code:
<?php
$hash = password_hash("secret", PASSWORD_BCRYPT);
var_dump(password_verify("secret", $hash));
var_dump(password_verify("secret" . chr(0) . "suffix", $hash));
?>
Resulted in this output:
bool(true)
bool(true)
But I expected this output instead:
bool(true)
bool(false)
PHP Version
all supported version
Operating System
No response
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
首先使用 password_hash()、password_verify()、PASSWORD_BCRYPT 和空字节复现该示例,然后跟踪 PHP 实现和现有的密码验证测试。当带有空字节后缀的密码不再能通过原始 bcrypt 哈希的验证,而未更改的密码仍能通过验证时,即表示完成。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- c, php
- 领域
- authentication, security
- Issue 类型
- 缺陷
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 活跃度
- 冷清
- 描述清晰度
- 基本清楚
- 新手友好度
- 48/100