php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #54299 Error in a comment about salt generation (crypto)
Submitted: 2011-03-18 04:56 UTC Modified: 2011-03-18 05:09 UTC
From: krewecherl at gmail dot com Assigned: aharvey (profile)
Status: Closed Package: Documentation problem
PHP Version: Irrelevant OS:
Private report: No CVE-ID: None
View Developer Edit
Welcome! If you don't have a Git account, you can't do anything here.
If you reported this bug, you can edit this bug over here.
(description)
Block user comment
Status: Assign to:
Package:
Bug Type:
Summary:
From: krewecherl at gmail dot com
New email:
PHP Version: OS:

 

 [2011-03-18 04:56 UTC] krewecherl at gmail dot com
Description:
------------
The comment by "thegreatall at gmail dot com" on the manual page for mt_rand() describes a method for quickly generating a pseudo-random salt for password hashes. One of the constants given in the example is incorrect and can lead a smaller range from which the random numbers will be selected.

The line -

  base_convert(mt_rand(0x1679616, 0x39AA3FF, 10, 36);

- should be changed to either -

  base_convert(mt_rand(1679616, 0x39AA3FF, 10, 36);

- or, if we want to keep the hex format, to -

  base_convert(mt_rand(0x19A100, 0x39AA3FF, 10, 36);

Rationale: the number 0x19A100 (= 1679616 in decimal) will be represented as 10000 in base-36, which is the intended value, whereas the given number 0x1679616 will be represented as e13iu in base-36.

Comment ID: 102318
Link: http://php.net/manual/en/function.mt-rand.php#102318


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2011-03-18 05:09 UTC] aharvey@php.net
-Status: Open +Status: Closed -Assigned To: +Assigned To: aharvey
 [2011-03-18 05:09 UTC] aharvey@php.net
Note updated; it'll take a little while to propagate out to the mirrors.

Thanks!
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Thu Oct 08 22:00:01 2026 UTC