4 ms·
The salt gets stored with the password hash in 'userstocreate.txt' so a line in userstocreate.txt looks something like: username:$6$salt$passwordhash$:email T
by nanch 14y ago
The salt gets stored with the password hash in 'userstocreate.txt' so a line in userstocreate.txt looks something like:
username:$6$salt$passwordhash$:email
Then the password is sent to the /etc/passwd (/etc/shadow) file by /usr/sbin/useradd in createusers.pl.
- Cyranix 14y agoNow that I'm waking up some more, I realize 1) you're correct, the salt is stored, but 2) you're using SHA-512 for password hashing, which has been repeatedly discussed as a bad idea for quite a while on HN. This is the last I'll say on it: I am genuinely glad that you're trying out a project of this complexity, but you have a responsibility not to give others a false sense of security. If you search HN, you will find plenty of advice and reading material -- restrict this app until you have absorbed more of it. It's not enough that it works; strive to make it work well. [Also, a nitpick just because it's killing me: please replace the entirety of isStringAllowed with a regular expression. \w{5,} would give you alphanumerics plus underscore and check for minimum length. Regexes don't solve every string-oriented problem, but they're a fantastic tool to have in your toolbelt.]
- rgbrgb 14y agoI disagree, congrats on releasing something! I think it is entirely appropriate to make it public and solicit feedback here. He has already gotten some useful stuff. Perhaps you could point him to "advice and reading material" that would be fruitful for him to "absorb" before he makes another gaff like getting on the front page of HN?
- jemfinch 14y agoWe don't need yet another scheme for managing passwords. If you can, use something like PHP's new password API: https://wiki.php.net/rfc/password_hash https://wiki.php.net/rfc/password_hash