|
|
|
|
|
by ErrantX
6250 days ago
|
|
Ok to prove what I am talking about (because it is only fair I do). Here are four 4 character password correctly hashed and salted. 6fe4bc5a51a3967a3a5e8d2f2baadd08db8cfa87934d88c142b7f89a 2faf5762d544eafaea9792e90660bfd224ffda2bb5f4dd4435a011ba 86096426b8cef5ebbf438a3f743b955100a4a0b4f72593af7485a1bb 0522e582fb1186fb79934998be7ee04f6c4a607009218fa3c35cffc6 The hash algorithm used is sha1. The salting scheme uses a randomly generated salt and a known salting roation.
I gave you 4 to give you fair chance to work on them. I'll give you more if you want. (there is no way to brute force these BTW so dont really bother :)) |
|
Running sha1() in PHP on each of the 98569 words in /usr/share/dict/words takes 1 second on my laptop. Appending all of the numbers 1-100 to each of those, not surprisingly ups the time to about 1m40s. You'll probably get quite a lot of users with passwords like that.