额外的尾随零(或缺失零)Java/PHP


Extra Trailing Zero (or missing zero) Java/PHP

Background

我正在开发一个 Bukkit 插件(Minecraft 服务器端)。该插件允许玩家相互来回发送消息。我也在开发一个网络界面。为了查看他们的"收件箱",他们必须首先使用可以在游戏中设置的密码登录。

此密码不是原始存储的,而是转换为一长串 unicode 值,然后分解成多个部分,每个部分转换为十六进制并附加到不同的字符串。

爪哇版本

//This isn't the best method, I know, but it's still going to take a genius to crack it.
//The resulting number (before somewhat converted to hex) is really
//long, there isn't an easy way of knowing the sequence of characters.
//This conversion is much different than straight up converting to hex,
//as PHP has certain limitations
public static String encodePassword(String password) {
    String longNumber = "";
    for(int i = 0; i < password.length(); i++) {
        longNumber += ((int) password.charAt(i));
    }
    //System.out.println("long = " + longNumber);
    String result = "";
    int splitLength = 5;
    int iterations = longNumber.length() / splitLength;
    if(longNumber.length() % splitLength > 0)
        iterations++;
    for(int i = 0; i < iterations; i++) {
        //System.out.println(result);
        int start = splitLength * i;
        if(longNumber.length() - start <= splitLength) {
            String sub = longNumber.substring(start);
            result += Integer.toHexString(Integer.parseInt(sub));
            continue;
        }
        String sub = longNumber.substring(start, start + splitLength);
        result += Integer.toHexString(Integer.parseInt(sub));
    }
    return result;
}

PHP版本

function encodePassword($pw){
    $unicode = "";
    for($i=0; $i<strlen($pw); $i++){
        $char = $pw{$i};
        $val = unicode_value($char);
        $unicode = $unicode.$val;
    }
    $result = "";
    $splitLength = 5;
    $iterations = strlen($unicode) / $splitLength;
    if(strlen($unicode) % $splitLength > 0)
        $iterations++;
    for($i = 0; $i < $iterations; $i++) {
        $start = $splitLength * $i;
        if(strlen($unicode) - $start <= $splitLength) {
            $sub = substr($unicode, $start);
            $result = $result.base_convert($sub, 10, 16);
            continue;
        }
        $sub = substr($unicode, $start, $splitLength);
        $result = $result.base_convert($sub, 10, 16);
    }
    return $result;
}

如果我"编码"密码"partychat"(插件的名称,它也具有群聊功能),我会在 Java 中得到2c212c93ef23163a91bcc,在 PHP 中得到2c212c93ef23163a91bcc0(除了尾随 0 之外相同)。我做错了什么?

注意:这并不总是发生,大多数"编码"工作正常,但由于某种原因,这种情况有时会发生

你为什么还要这个,我只会使用用户密码的哈希值,例如: 这个关于 SHA-256 的堆栈溢出问题,我知道它不能解决您的问题,但不发明自己的加密标准:)

更安全