gpt4 book ai didi

php - 哈希字符串在插入数据库时​​被截断

转载 作者:行者123 更新时间:2023-11-30 23:20:21 26 4
gpt4 key购买 nike

我有一个奇怪的问题。我将发布两段代码,希望能阐明我的问题。以下代码根据用户输入的密码创建哈希,我使用的是 hmac 和 bcrypt:

if(isset($_POST['username'])){
$username = preg_replace('#[^a-z0-9]#i', '', $_POST['username']);
$email1 = strip_tags($_POST['email1']);
$email2 = strip_tags($_POST['email2']);
$pass1 = strip_tags($_POST['pass1']);
$pass2 = strip_tags($_POST['pass2']);
// make sure no fields are blank /////
if(trim($username) == "" || trim($email1) == "" || trim($pass1) == "" || trim($pass2) == ""){
echo "Error: All fields are required. Please press back in your browser and try again.";
$db = null;
exit();
}
/// Make sure both email fields match /////
if($email1 != $email2){
echo "Your email fields do not match. Press back and try again";
exit();
}
//// Make sure both password fields match ////
else if($pass1 != $pass2){
echo "Your password fields do not match. Press back and try again";
exit();
}
//// create the hmac /////
$hmac = hash_hmac('sha512', $pass1, file_get_contents('my/path/to/key.txt'));
//// create random bytes for salt ////
$bytes = mcrypt_create_iv(16, MCRYPT_DEV_URANDOM);
//// Create salt and replace + with . ////
$salt = strtr(base64_encode($bytes), '+', '.');
//// make sure our bcrypt hash is 22 characters which is the required length ////
$salt = substr($salt, 0, 22);
//// This is the hashed password to store in the db ////
$bcrypt = crypt($hmac, '$2y$12$' . $salt);
echo $bcrypt;

这段代码工作得很好,并创建了一个看起来像这样的散列:

$2y$12$Oysi/5oZjF4vlUYx4PvgJ.GSpAQb7njNzSTUnEy/QOFzPxqRpHFV6

我遇到的问题是在执行一些错误处理然后插入数据后,散列密码被切断。只是想让你知道我存储它的字段最初设置为 VARCHAR(255),我什至将它更改为 TEXT,但它仍然被切断。下面是我刚刚输出上面密码的其余代码:

//// Create token for activation script ////
$token = md5($bcrypt);
//// query to check if email is in the db already ////
$stmt = $db->prepare("SELECT email FROM members WHERE email=:email1 LIMIT 1");
$stmt->bindValue(':email1',$email1,PDO::PARAM_STR);
try{
$stmt->execute();
$count = $stmt->rowCount();
}
catch(PDOException $e){
echo $e->getMessage();
$db = null;
exit();
}
//// query to check if the username is in the db already ////
$unameSQL = $db->prepare("SELECT username FROM members WHERE username=:username LIMIT 1");
$unameSQL->bindValue('username',$username,PDO::PARAM_STR);
try{
$unameSQL->execute();
$unCount = $unameSQL->rowCount();
}
catch(PDOException $e){
echo $e->getMessage();
$db = null;
exit();
}
///Check if email is in the db already ////
if($count > 0){
echo "Sorry, that email is already in use in the system";
$db = null;
exit();
}
//// Check if username is in the db already ////
if($unCount > 0){
echo "Sorry, that username is already in use in the system";
$db = null;
exit();
}
try{
$db->beginTransaction();
$ipaddress = getenv('REMOTE_ADDR');
$stmt2 = $db->prepare("INSERT INTO members (username, email, password, signup_date, ipaddress) VALUES (:username, :email1, :bcrypt, now(), :ipaddress)");
$stmt2->bindParam(':username', $username, PDO::PARAM_STR);
$stmt2->bindParam(':email1',$email1,PDO::PARAM_STR);
$stmt2->bindParam(':bcrypt',$bcrypt,PDO::PARAM_STR);
$stmt2->bindParam(':ipaddress',$ipaddress,PDO::PARAM_INT);
$stmt2->execute();
/// Get the last id inserted to the db which is now this users id for activation and member folder creation ////
$lastId = $db->lastInsertId();
$stmt3 = $db->prepare("INSERT INTO activate (user, token) VALUES ('$lastId', :token)");
$stmt3->bindValue(':token',$token,PDO::PARAM_STR);
$stmt3->execute();
//// Send email activation to the new user ////
$from = "From: Auto Resposder @ GotCode <admin@gotcode.org>";
$subject = "IMPORTANT: Activate your gotCode account";
$link = 'http://www.gotcode.org/activate.php?user='.$lastId.'&token='.$token.'';
//// Start Email Body ////
$message = "
Thanks for registering an account at gotCode.org! Were glad you decided to join us in this wacky adventure.
Theres just one last step to set up your account. Please click the link below to confirm your identity and get started.
If the link below is not active please copy and paste it into your browser address bar. See you on the site!

$link
";
//// Set headers ////
$headers = 'MIME-Version: 1.0' . "rn";
$headers .= "Content-type: textrn";
$headers .= "From: $fromrn";
/// Send the email now ////
mail($email1, $subject, $message, $headers, '-f noreply@mywebsite.org');
$db->commit();
echo "Thanks for joining! Check your email in a few moments to activate your account so that you may log in. See you on the site!<br />$bcrypt<br />$hmac<br />$salt<br />$token";
exit();
$db = null;
exit();
}
catch(PDOException $e){
$db->rollBack();
echo $e->getMessage();
$db = null;
exit();
}
}

代码的其余部分在将数据插入数据库以及发送我的电子邮件激活时同样有效。问题是现在哈希密码存储在数据库中,如下所示:

$2hm7KFNCFyfM

我真的很难弄清楚为什么当我只是回显散列密码时它是一个很好的长散列字符串,正如预期的那样,但在错误检查并插入到数据库之后它被切断了。也许多一双眼睛可以发现我的错误?非常感谢!

最佳答案

好吧...要解决此问题,我只需将我的 php 版本从 5.2 升级即可。

更具体地说明问题是什么:对于 PHP < 5.3 当使用河豚算法时应该使用

$2a$

大于 PHP 5.2 使用

$2y$

换句话说,如果不更新我的 php 版本,解决此问题的方法是更改​​此行:

$bcrypt = crypt($hmac, '$2y$12$' . $salt);

对此:

$bcrypt = crypt($hmac, '$2a$12$' . $salt);

以防万一有人遇到同样的问题:)

关于php - 哈希字符串在插入数据库时​​被截断,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/15795406/

26 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com