hash_equals
(PHP 5 >= 5.6.0, PHP 7)
hash_equals — Timing attack safe string comparison
Description
$known_string
, string $user_string
) : boolCompares two strings using the same time whether they're equal or not.
This function should be used to mitigate timing attacks; for instance, when testing crypt() password hashes.
Parameters
-
known_string
-
The string of known length to compare against
-
user_string
-
The user-supplied string
Errors/Exceptions
Emits an E_WARNING
message when either of the
supplied parameters is not a string.
Examples
Example #1 hash_equals() example
<?php
$expected = crypt('12345', '$2a$07$usesomesillystringforsalt$');
$correct = crypt('12345', '$2a$07$usesomesillystringforsalt$');
$incorrect = crypt('apple', '$2a$07$usesomesillystringforsalt$');
var_dump(hash_equals($expected, $correct));
var_dump(hash_equals($expected, $incorrect));
?>
The above example will output:
bool(true) bool(false)
Notes
Note:
Both arguments must be of the same length to be compared successfully. When arguments of differing length are supplied,
FALSE
is returned immediately and the length of the known string may be leaked in case of a timing attack.
Note:
It is important to provide the user-supplied string as the second parameter, rather than the first.
English translation
You have asked to visit this site in English. For now, only the interface is translated, but not all the content yet.If you want to help me in translations, your contribution is welcome. All you need to do is register on the site, and send me a message asking me to add you to the group of translators, which will give you the opportunity to translate the pages you want. A link at the bottom of each translated page indicates that you are the translator, and has a link to your profile.
Thank you in advance.
Document created the 30/01/2003, last modified the 26/10/2018
Source of the printed document:https://www.gaudry.be/en/php-rf-function.hash-equals.html
The infobrol is a personal site whose content is my sole responsibility. The text is available under CreativeCommons license (BY-NC-SA). More info on the terms of use and the author.
References
These references and links indicate documents consulted during the writing of this page, or which may provide additional information, but the authors of these sources can not be held responsible for the content of this page.
The author This site is solely responsible for the way in which the various concepts, and the freedoms that are taken with the reference works, are presented here. Remember that you must cross multiple source information to reduce the risk of errors.