Web Hack List

Collected research

Hash Information Disclosure Via Collisions - The Hard Way

Hash Information Disclosure Via Collisions - The Hard Way ha.ckers.org web application security lab

A thought experiment on using precomputed hash collisions as a fingerprinting oracle. Registering a password and then logging in with a known colliding string reveals which hashing algorithm and salting scheme a site uses. The same trick extends to password blacklist evasion and to databases whose primary key is a hash of known data.

Record

Document
Hash Information Disclosure Via Collisions - The Hard Way ha.ckers.org web application security lab
Published by
ha.ckers.org
Topic
Crypto

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of ha.ckers.org, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .