note 25119 added to function.md5
| From: | karl dot vegar at NO dot SPAMsofthome dot net | Date: | Wed, 11 Sep 2002 11:01:19 +0000 |
| Subject: | note 25119 added to function.md5 | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-36506@lists.php.net to get a copy of this message | ||
A small comment on the possibility of brute force'ing.
While, as Marc stated earlier, it will take, in all practical use, forever to brute force if you md5
hash the result before you test it.
It is another matter entirely to brute force against the md5 string itself.
If password is stored md5 hashed, and the login rutine only test against this string, it might be
possible to bypass the part that md5 hash'es the password, and test against the md5 string
itself, thus shortening both the loop, and the number of chars.
Yet another agrument why you shouuld add some random bytes with every session. You can't
effectively brute force a string that changes randomly every time you test against it...
--
http://www.php.net/manual/en/function.md5.php
http://master.php.net/manage/user-notes.php?action=edit+25119
http://master.php.net/manage/user-notes.php?action=delete+25119
http://master.php.net/manage/user-notes.php?action=reject+25119