BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Apache web server 2.2: htpasswd predictable salt weakness Feb 15 2008 05:44PM
3APA3A (3APA3A SECURITY NNOV RU)
Dear Peter Watkins,

--Thursday, February 14, 2008, 5:55:17 AM, you wrote to bugtraq (at) securityfocus (dot) com [email concealed]:

PW> As a result:
PW> - Salts created by htpasswd are very predictable.
PW> - The universe of salts for htpasswd is far less than the MD5 algorithm
PW> provides for -- 29 bits vs. 48, or 0....

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus