瀏覽代碼

[Security] improved entropy to make collision attacks harder

Johannes Schmitt 14 年之前
父節點
當前提交
f010742e45
共有 1 個文件被更改,包括 1 次插入1 次删除
  1. 1 1
      src/Symfony/Component/Security/Core/Encoder/MessageDigestPasswordEncoder.php

+ 1 - 1
src/Symfony/Component/Security/Core/Encoder/MessageDigestPasswordEncoder.php

@@ -49,7 +49,7 @@ class MessageDigestPasswordEncoder extends BasePasswordEncoder
 
         // "stretch" hash
         for ($i = 1; $i < $this->iterations; $i++) {
-            $digest = hash($this->algorithm, $digest, true);
+            $digest = hash($this->algorithm, $digest.$salted, true);
         }
 
         return $this->encodeHashAsBase64 ? base64_encode($digest) : bin2hex($digest);