note 90144 deleted from security.database.storage by joey
| From: | joey@php.net | Date: | Wed, 28 Dec 2011 08:42:07 +0000 |
| Subject: | note 90144 deleted from security.database.storage by joey | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-185261@lists.php.net to get a copy of this message | ||
Note Submitter: centurion54 at hotmail dot com
----
I'm using this function to hash my passwords. The important aspect of it is that the salt is
longer then the password hash, this creates collisions which is the only complete protection against
brute-force attacks. This script creates 16 collisions for every iteration. Also, the salt is stored
as the first 88 characters of the hash which makes it accessible for validation. Hash total length
is 128 hex.
The hash will never be the same but is still possible to validate. Wow!
<?php
/**
* Created by Gustav Svalander 2009
* Hash string using a salt, if no salt is specified it is
* randomly generated.
* @param String Information to be hashed.
* @param String Hashing salt.
* @return String One string beginning with the salt then the hash
*/
function xerHash($information,$salt=null){
$result = utf8_encode($information);
if($salt == null)
for($i=0;$i<88;$i++)
$salt.=dechex(rand(0,15));
for($i=0;$i<3000;$i++){
$result = sha1($salt.$result);
}
return ($salt.$result);
}
//Test
$hash = superHash("test");
$validation = superHash("test",substr($hash,0,88));
echo 'Hashing:"test"<br>Hash:'.$hash.'<br>Hash
validation:'.$validation;
?>
MD5/SHA1 is not safe for strings shorter then 10 characters. Especially if you don't use a
strong combination.
Cracking this hash would result in having 4,3046721e+55 possible passwords.