4 ms·
The article says that they used the injection to get hashed login credentials. Did they then use a rainbow table to reverse the hashing?
by acv 13y ago
The article says that they used the injection to get hashed login credentials. Did they then use a rainbow table to reverse the hashing?
- dgroves 13y agoPrecisely why hash(salt+password) is no longer sufficient. An HSM is require with keys known to nobody (backup HSM's locked in a safe) but the password hashing machine. In a nutshell it should be more like this: Hash(hsm_keys+salt+password) Of course all the usual things about entropy still apply, that string should be at least 256 bytes (256 bits of entropy is 32 bytes, so I am advocating much, much more), and that will likely only keep you safe until the next generation of ASIC computers are released.
- meowface 13y agoThere are a wide myriad of ways that plaintext can be derived from password hashes. Rainbow tables are an option if they're not salted; otherwise the attackers likely had access to fairly significant computing power (considering the amount of money they were raking in) to perform typical dictionary + bruteforce attacks on them.