note 25119 deleted from function.md5 by jimw
| From: | jimw@php.net | Date: | Sat, 08 Feb 2003 19:50:00 +0000 |
| Subject: | note 25119 deleted from function.md5 by jimw | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-43645@lists.php.net to get a copy of this message | ||
A small comment on the possibility of brute force'ing.
While, as Marc stated earlier, it will take, in all practical use, forever to brute force if you md5
hash the result before you test it.
It is another matter entirely to brute force against the md5 string itself.
If password is stored md5 hashed, and the login rutine only test against this string, it might be
possible to bypass the part that md5 hash'es the password, and test against the md5 string
itself, thus shortening both the loop, and the number of chars.
Yet another agrument why you shouuld add some random bytes with every session. You can't
effectively brute force a string that changes randomly every time you test against it...