note 90144 deleted from security.database.storage by joey

From: Date: Wed, 28 Dec 2011 08:42:07 +0000
Subject: note 90144 deleted from security.database.storage by joey
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-185261@lists.php.net to get a copy of this message
Note Submitter: centurion54 at hotmail dot com ---- I'm using this function to hash my passwords. The important aspect of it is that the salt is longer then the password hash, this creates collisions which is the only complete protection against brute-force attacks. This script creates 16 collisions for every iteration. Also, the salt is stored as the first 88 characters of the hash which makes it accessible for validation. Hash total length is 128 hex. The hash will never be the same but is still possible to validate. Wow! <?php /** * Created by Gustav Svalander 2009 * Hash string using a salt, if no salt is specified it is * randomly generated. * @param String Information to be hashed. * @param String Hashing salt. * @return String One string beginning with the salt then the hash */ function xerHash($information,$salt=null){ $result = utf8_encode($information); if($salt == null) for($i=0;$i<88;$i++) $salt.=dechex(rand(0,15)); for($i=0;$i<3000;$i++){ $result = sha1($salt.$result); } return ($salt.$result); } //Test $hash = superHash("test"); $validation = superHash("test",substr($hash,0,88)); echo 'Hashing:"test"<br>Hash:'.$hash.'<br>Hash validation:'.$validation; ?> MD5/SHA1 is not safe for strings shorter then 10 characters. Especially if you don't use a strong combination. Cracking this hash would result in having 4,3046721e+55 possible passwords.

« previous php.notes (#185261) next »