BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Apache web server 2.2: htpasswd predictable salt weakness Feb 15 2008 09:07PM
Peter Watkins (peterw usa net)
On Fri, Feb 15, 2008 at 08:44:08PM +0300, 3APA3A wrote:

> PW> As a result:
> PW> - Salts created by htpasswd are very predictable.
> PW> - The universe of salts for htpasswd is far less than the MD5 algorithm
> PW> provides for -- 29 bits vs. 48, or 0.000191 percent of the range that
> PW> ...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus