3 ms·
A useful hack I've implemented in several projects is to accept the stored password hash as a valid password. It is generally possible to impersonate a user bu
by ht85 4y ago
A useful hack I've implemented in several projects is to accept the stored password hash as a valid password.
It is generally possible to impersonate a user but there are always subtle differences in the way those sessions work.
Accepting the hash lets people with database access perform a real login if needed.
- LouisSayers 4y ago> Accepting the hash lets people with database access perform a real login if needed. ... and if anyone managed to say do an SQL injection and retrieve said hashes, then that then would give them access to your users accounts, right?
- alexchantavy 4y agoAnd also access to those users’ other accounts if they reuse passwords (most people probably do)
- LouisSayers 4y agoKnowing hashes alone wouldn't allow you to do this normally - usually you use a "salt" during the hashing process which would lead to different hashes with the same password. Without doing the OP's "trick" however, if you somehow managed to get a hashed and salted password then it still wouldn't be enough to gain access to someone's account.
- ht85 4y agoYes it would and might be a reason you would not want to do this, although nobody would try to login using hashes unless they also have access to your source code (or read that comment I guess? :D).