October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk2 min

Why the Same PHP Hash Function Returns Different Outputs

The SitePoint mismatch came from 1234568 versus 12345678. Check the exact input bytes and line endings before debugging a PHP hash function.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The values in the SitePoint example were not the same: the password file contained 1234568, while the PHP code compared against 12345678. The missing 7 is enough to produce a different digest. Hash functions operate on their actual input bytes, so check the strings being hashed before suspecting a PHP-version difference.

What caused the different hash outputs?

The SitePoint discussion eventually identified a typo: the file contained 1234568, but the hard-coded value was 12345678. Those are different strings, so a deterministic hash function produces different outputs for them. The original discussion is [Two same hash function with same values return different outputs].

This is not explained by PHP changing the result for identical input. The practical distinction is between the value you think you are hashing and the bytes the program actually passes to the hash function.

Inspect the input before debugging the hash

Print a quoted representation and the string length so that invisible characters and missing digits are easier to spot:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
$file = fopen('passwords.txt', 'r');
$line = fgets($file);
var_dump($line, strlen($line));
var_dump(trim($line) === '12345678');

var_dump() shows the string representation and its length; the strict comparison reports whether the trimmed value exactly matches the expected string. In this example, if the file contains 1234568, trimming cannot add the missing 7.

Account for line endings deliberately

PHP’s fgets() reads a line and includes the newline in the returned string when it encounters one. The PHP manual describes the stopping rule: “Reading ends when length – 1 bytes have been read, or a newline (which is included in the return value), or an EOF (whichever comes first).” See PHP’s fgets() documentation.

If the file format defines one password per line and the line ending is only a delimiter, remove that ending intentionally before comparing or hashing. For example, trim($line) removes whitespace from both ends by default, but it does not remove characters in the middle or repair a typo. Its default removal set is documented in the PHP trim() manual. Do not use trimming automatically if leading or trailing spaces are meaningful in your input format.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Use password-specific APIs for account passwords

MD5 and SHA-1, including compositions that apply one digest after another, are general-purpose digest constructions—not encryption and not an appropriate new design for storing account passwords. Stacking digests does not provide the password-hashing properties intended by PHP’s password APIs or OWASP guidance. A classroom exercise or a legacy conversion task may have different constraints; for live credentials, use a password-hashing API.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For new password storage, PHP’s standard pattern is:

$hash = password_hash($password, PASSWORD_DEFAULT);

if (password_verify($candidate, $hash)) {
    // Password matches.
}

password_hash() creates a hash using a strong one-way algorithm, generates a random salt by default, and stores the algorithm, cost, and salt information in the resulting hash string. password_verify() checks a candidate against that string. Consult the PHP password_hash() documentation and PHP password_verify() documentation for the algorithms available to your PHP version and operational settings. PHP’s default algorithm may change as stronger options are added, so retain the complete generated hash rather than separating its components. OWASP’s Password Storage Cheat Sheet provides broader guidance on algorithm choice and work factors for deployment environments.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.