php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #66835 password_verifiy
Submitted: 2014-03-06 13:39 UTC Modified: 2014-03-06 14:29 UTC
From: pl dot lamballais at flashover dot fr Assigned:
Status: Not a bug Package: *General Issues
PHP Version: 5.5.10 OS: Linux
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: pl dot lamballais at flashover dot fr
New email:
PHP Version: OS:

 

 [2014-03-06 13:39 UTC] pl dot lamballais at flashover dot fr
Description:
------------
---
From manual page: http://www.php.net/function.password-verify
---

System is:Linux webd497.20gp.ha.ovh.net 3.10.23-grsec-mutu-grs-ipv6-64+ #42 SMP Wed Feb 26 12:45:33 CET 2014 x86_64 

PHP version is 5.5.7

Notice a strange comportemnt of password_verify() depending on the fact the hash variable is using ' or ".
I start to think this affect also the hash builder as I've some user records in my database which are seen as "correct" using password_verify and others which are seen as "bad password" when in fact they are all build the same way.

Test script:
---------------
// First exemple will give "Password is valid!"
$hash = '$2y$07$BCryptRequires22Chrcte/VlQH0piJtjXl.0t1XkA8pw9dMXTpOq';

if (password_verify('rasmuslerdorf', $hash))
{
    echo 'Password is valid!';} else {
    echo 'Invalid password.';}

// But this one will will give "Invalid password!"
$hash = "$2y$07$BCryptRequires22Chrcte/VlQH0piJtjXl.0t1XkA8pw9dMXTpOq";

if (password_verify('rasmuslerdorf', $hash))
{
    echo 'Password is valid!';} else {
    echo 'Invalid password.';}


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2014-03-06 13:44 UTC] nikic@php.net
-Status: Open +Status: Not a bug
 [2014-03-06 13:44 UTC] nikic@php.net
"...$BCryptRequires22Chrcte..." will interpolate the value of the variable $BCryptRequires22Chrcte into the string. I would recommend to enable notices during development.
 [2014-03-06 14:29 UTC] pl dot lamballais at flashover dot fr
Agree with nikic, not really a bug.
Maybe a good thing will be to add a note about that on the doc. Because I notice that, depending on the hash, some are working with ' or "" and others not... :/
This means you can do your dev, test and if, unfortunatly the hash used for test are good even with ' or " you'll have some problems... later.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Thu Oct 08 02:00:01 2026 UTC