3 ms·
Realize that the attacker must first possess the user/password database for this to work. This is because the author takes the salt from that information. Witho
by SmallPeePeeMan 6y ago
Realize that the attacker must first possess the user/password database for this to work. This is because the author takes the salt from that information. Without the salt, it will take much longer to brute force... even though it’s md5 hashed.
- weewee2018 6y agoHow is he getting the salt from the database?
- shoo 6y agothis corresponds to sad scenario where the database itself is leaked and the attacker has access to it. the blog describes how the salt is stored as prefix to each hash.