note 25119 deleted from function.md5 by jimw

From: Date: Sat, 08 Feb 2003 19:50:00 +0000
Subject: note 25119 deleted from function.md5 by jimw
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-43645@lists.php.net to get a copy of this message
A small comment on the possibility of brute force'ing. While, as Marc stated earlier, it will take, in all practical use, forever to brute force if you md5 hash the result before you test it. It is another matter entirely to brute force against the md5 string itself. If password is stored md5 hashed, and the login rutine only test against this string, it might be possible to bypass the part that md5 hash'es the password, and test against the md5 string itself, thus shortening both the loop, and the number of chars. Yet another agrument why you shouuld add some random bytes with every session. You can't effectively brute force a string that changes randomly every time you test against it...

« previous php.notes (#43645) next »