in reply to OT: Cracking hashes made easier
A lookup table doesn't help you if the (MD5) hashing is set up correctly:
my $secret = "Secret Passphrase"; my $password = get_password; my $salt = get_username; die unless $password; die unless $salt; my $md5 = md5($secret.$password.$salt);
That way, as long as the $secret remains secret, the hash lookup cannot be reversed to something you would enter in the password entry field, unless all entries in the hash lookup list have the same (secret) prefix.
Of course, if you can create enough users (and passwords), you can try an attack to recover $secret.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: OT: Cracking hashes made easier
by thor (Priest) on Nov 11, 2005 at 14:49 UTC | |
by tilly (Archbishop) on Nov 11, 2005 at 18:17 UTC | |
by thor (Priest) on Nov 11, 2005 at 20:02 UTC | |
by tilly (Archbishop) on Nov 11, 2005 at 22:05 UTC | |
by DrHyde (Prior) on Nov 14, 2005 at 11:40 UTC | |
by thor (Priest) on Nov 14, 2005 at 12:11 UTC | |
by DrHyde (Prior) on Nov 16, 2005 at 11:01 UTC | |
by thor (Priest) on Nov 16, 2005 at 12:16 UTC | |
|