Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Wed, 17 Jun 2015 00:19:21 +0200
From: magnum <>
Subject: #saltfail

Nice post by Atom

The context is ColdFusion's sha256($salt.sha1($pass)) but the hash 
functions are not important, it applies to things like MD5(salt.pass) as 
well. The flaw is it's a salt with a length that "equals or is greater 
than the blocksize of the hash" and that it's prepended to the password, 
as opposed to appended. This means, in JtR context, we can run the first 
digest operation in get_salt() and get it completely out of the hot loops.

We have formats that already use this optimization but we probably have 
some that don't. We should list them and fix them.


Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.