Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re[2]: Apache web server 2.2: htpasswd predictable salt weakness Feb 16 2008 04:10PM
3APA3A (3APA3A SECURITY NNOV RU)
Dear Peter Watkins,

PW> I don't know how small the salt universe would need to be before
PW> precomputing dictionaries would be worthwhile (vs. having a botnet only work
PW> on crypted passwords already captured), but certainly the obviously weak
PW> srand(time(NULL)) code only helps the black hats...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus