php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #54299 Error in a comment about salt generation (crypto)
Submitted: 2011-03-18 04:56 UTC Modified: 2011-03-18 05:09 UTC
From: krewecherl at gmail dot com Assigned: aharvey (profile)
Status: Closed Package: Documentation problem
PHP Version: Irrelevant OS:
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: krewecherl at gmail dot com
New email:
PHP Version: OS:

 

 [2011-03-18 04:56 UTC] krewecherl at gmail dot com
Description:
------------
The comment by "thegreatall at gmail dot com" on the manual page for mt_rand() describes a method for quickly generating a pseudo-random salt for password hashes. One of the constants given in the example is incorrect and can lead a smaller range from which the random numbers will be selected.

The line -

  base_convert(mt_rand(0x1679616, 0x39AA3FF, 10, 36);

- should be changed to either -

  base_convert(mt_rand(1679616, 0x39AA3FF, 10, 36);

- or, if we want to keep the hex format, to -

  base_convert(mt_rand(0x19A100, 0x39AA3FF, 10, 36);

Rationale: the number 0x19A100 (= 1679616 in decimal) will be represented as 10000 in base-36, which is the intended value, whereas the given number 0x1679616 will be represented as e13iu in base-36.

Comment ID: 102318
Link: http://php.net/manual/en/function.mt-rand.php#102318


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2011-03-18 05:09 UTC] aharvey@php.net
-Status: Open +Status: Closed -Assigned To: +Assigned To: aharvey
 [2011-03-18 05:09 UTC] aharvey@php.net
Note updated; it'll take a little while to propagate out to the mirrors.

Thanks!
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Sat Oct 10 00:00:01 2026 UTC