Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
hashes — Magic hashes – PHP hash "collisions" | Kitploit
Tools/GitHubGitHub/spaze/hashes
Vulnerability AnalysisHash AnalysisWeb SecurityCryptographyLearning & EducationCurated Resources
GitHubspaze/hashes

hashes

Magic hashes – PHP hash "collisions"

View Repository
835103671 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Magic hashes – PHP hash "collisions"

Register with password 1 and then sign in with password 2. If you're in then the storage uses specified algorithm to hash the password and PHP uses == to compare them (for MD5, SHA-1, and plaintext).

MD5, SHA-1, SHA-224, SHA-256 and others

For MD5, SHA-1 and SHA-2 family, it uses the long-known trick (it actually is a documented feature, see PHP type comparison tables & Floating point numbers) that for PHP '0e1' == '00e2' == '0', it just uses it for practical purposes. Any password matches any other password from the list. This is a different trick than integral strings overflowing into floating point numbers, just spot the difference between these two lines.

These are all the algorithms with magic hashes:

  • CRC32
  • CRC32b
  • FNV-1a/32
  • FNV-1a/64
  • FNV-1/32
  • FNV-1/64
  • HAVAL-128,3
  • HAVAL-128,4
  • HAVAL-128,5
  • HAVAL-160,3
  • HAVAL-160,4
  • HAVAL-160,5
  • JOAAT
  • MD2
  • MD4
  • MD5
  • MD5-double md5(md5(password))
  • MurmurHash3_x86_32/Murmur3a
  • MurmurHash3_x86_128/Murmur3c
  • MurmurHash3_x64_128/Murmur3f
  • PHOTON-80/20/16
  • PHOTON-128/16/16
  • PHOTON-160/36/36
  • Quark u-Quark-136
  • RIPEMD-128
  • RIPEMD-160
  • SHA-1
  • SHA-224
  • SHA-256
  • SPONGENT-88/80/8
  • SPONGENT-88/176/88
  • SPONGENT-128/128/8
  • SPONGENT-128/256/128
  • Tiger/128,3
  • Tiger/128,4
  • Tiger/160,3
  • Tiger/160,4
  • Tiger/192,3
  • xxHash-XXH32
  • xxHash-XXH64
  • xxHash-XXH3_64bits
  • xxHash-XXH3_128bits

To quote @0xb0bb, "there are other applications for magic hashes other than password comparisons (such as caching layers or data derived from the output of a hash function) where these known insecure, lesser known and pseudo-hash algorithms can be found more readily."

Plaintext

For plaintext, it uses various conversion tricks. First password will match just the second one. Tricks are grouped by PHP versions allowing them.

bcrypt

bcrypt truncates passwords to a maximum length of 72 characters. The passwords match if the first 72 characters of both passwords match.

descrypt

descrypt (traditional UNIX DES crypt) truncates passwords to a maximum length of 8 characters. The passwords also match if the first 8 characters of both passwords match, see the "General cross-check" section.

PBKDF2-HMAC-SHA1, PBKDF2-HMAC-SHA224, PBKDF2-HMAC-SHA256

If you use a password longer than 64 bytes and hash it with PBKDF2-HMAC-SHA1, it is first pre-hashed with SHA1, so PBKDF2-HMAC-SHA1(password1) === PBKDF2-HMAC-SHA1(password2) because sha1(password1) === bin2hex(password2). The similar pre-hashing is applied in case of PBKDF2-HMAC-SHA224 and PBKDF2-HMAC-SHA256.

Tiger/192,3

Right now there's just one magic hash in each thanks to Norbert Tihanyi, more will be hopefully added in the future.

Conclusion

Use === when comparing anything* in PHP, not ==. And use password_hash() and password_verify() for password hashing in PHP, don't use MD5 or SHA-1. *Use hash_equals() when comparing hashes.

History

It all started with this tweet, I've generated QNKCDZO and 240610708 in February 2014 and it has since spread all over the intertubes. Just google it.

Download Tool