We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 15001
    • 697 Posts
    Hi,

    I need to cipher something on the server side and to decrypt it on the client side.
    For this, I chose to use the RC4 algorithm, offering symetric encryption/decryption.

    I tried the RC4 php/js functions found here: http://farhadi.ir/works/rc4

    For simple strings it worked fine, but I got problems when trying to cipher/uncipher a XHTML form. Globally, the deciphering works fine, but a few chars are replaced with wrong ones.

    e.g.
     <inp~t type="hidden" name="notify_url" value="http://localhost/testing/index.php?id=132&actioe=ipn" />
    + <input type="hiddee"

    Maybe the problem could come from special chars, not recognized the same way on the server and client sides.

    (skip)
      • 15001
      • 697 Posts

      Solved ! grin

      The problem was due to the fact that these PHP ~ Javascript functions are not truly the same:
      url_encode() ~ escape()
      url_decode() ~ solution()

      Solution

      As explained here, a possible solution is using Javascript equivalents of the url_encode() / url_decode() functions:
      http://www.pointwriter.com/blog/index.php?/archives/3-urlencode-for-JavaScript.html

      To find the URLDecode function I followed the link to "The URLEncode and URLDecode Page": http://www.albionresearch.com/misc/urlencode.php
      looked at the source and slightly modified the URLDecode() function so that it accepts an argument instead of retrieving its ciphered text from a form input field.

      It works perfectly.
      On server side, the RC4 encoding can be done with one of this two calls:

      $ciphered_paypal_form_content = endecrypt($cipherKey,$toCipher,'');

      or
      $ciphered_paypal_form_content = urlencode(rc4Encrypt($cipherKey,$toCipher));


      where the endecrypt function is the one found in manager/includes/crypt.class.inc.php,
      while the rc4Encrypt function comes with http://farhadi.ir/works/rc4.

      On the client side, the decryption is done this way:
      var deciphered = rc4Decrypt(k,URLDecode(document.getElementById('cfc').value));


      Note: if your site is in utf-8, since the rc4Encrypt function does not accept utf-8, you would maybe need to insert additional utf8_encode() on the server side and most probably a call to UTFDecode() on the client side.

      UTF8Decode() Javascript function can be found at the following address http://farhadi.ir/works/utf8.