Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Page 2 of 4 FirstFirst 1234 LastLast
Results 11 to 20 of 35
  1. #11
    Join Date
    May 2005
    Location
    /etc/passwd
    Posts
    19,110
    Tokens
    1,139

    Latest Awards:

    Default

    Can I just input here, how is MD5 "not secure"? It's only the fools who put dictionary words as their passwords that are going to be effected.

    If you forced them to set a password with even one character of punctuation it's going to make cracking the password take a whole lot longer (IMO people should be forced to do this, just my 2c)
    Last edited by Recursion; 30-08-2010 at 10:36 AM.
    Quote Originally Posted by Chippiewill View Post
    e-rebel forum moderator
    :8

  2. #12
    Join Date
    Jul 2007
    Location
    UK
    Posts
    2,470
    Tokens
    2,975

    Latest Awards:

    Default

    Quote Originally Posted by Recursion View Post
    Can I just input here, how is MD5 "not secure"? It's only the fools who put dictionary words as their passwords that are going to be effected.

    If you forced them to set a password with even one character of punctuation it's going to make cracking the password take a whole lot longer (IMO people should be forced to do this, just my 2c)
    Currently the password has to be longer than 6 charaters i think. i may add the salt, but im not right now,MD5 should be fine.

    UPDATE: User CP is almost done. About me editing is done, Including BB Code. Show and hide DoB, Email, and Name is working. change password is done, and change email is done.

  3. #13
    Join Date
    Nov 2005
    Posts
    4,486
    Tokens
    921

    Latest Awards:

    Default

    Just make sure you cover all the exploits.
    "RETIRED" FROM HABBO(X)

    :¬:

    TOMSPIT / COWLY05


  4. #14
    Join Date
    Jul 2004
    Location
    California
    Posts
    8,725
    Tokens
    3,789
    Habbo
    HotelUser

    Latest Awards:

    Default

    Quote Originally Posted by Recursion View Post
    Can I just input here, how is MD5 "not secure"? It's only the fools who put dictionary words as their passwords that are going to be effected.

    If you forced them to set a password with even one character of punctuation it's going to make cracking the password take a whole lot longer (IMO people should be forced to do this, just my 2c)
    Agreed Tom, and it only takes a little elbow grease to implement too


    Quote Originally Posted by Techie! View Post
    Currently the password has to be longer than 6 charaters i think. i may add the salt, but im not right now,MD5 should be fine.

    UPDATE: User CP is almost done. About me editing is done, Including BB Code. Show and hide DoB, Email, and Name is working. change password is done, and change email is done.
    Excellent stuff. Especially interested in what you said about bbcode. Do you have a WYSIWYG bbcose editor?

  5. #15
    Join Date
    Jul 2007
    Location
    UK
    Posts
    2,470
    Tokens
    2,975

    Latest Awards:

    Default

    Quote Originally Posted by HotelUser View Post
    Agreed Tom, and it only takes a little elbow grease to implement too




    Excellent stuff. Especially interested in what you said about bbcode. Do you have a WYSIWYG bbcose editor?
    Currently the BBCode has to be added manually, [br] ect, i may add a wysiwyg editor, just want to get everything working first. Also may be overhauling the PM system, seems a lil buggy using ajax.

  6. #16
    Join Date
    Nov 2008
    Location
    Cambridge, UK
    Posts
    901
    Tokens
    100

    Default

    Quote Originally Posted by Blob View Post
    I salt password strings like

    md5( $username . $password . $salt );

    where salt is

    substr( md5( time() ), 0, 8 )

    and stored in the users row
    Your salt is dynamic based on a number that will never happen again? Good luck with that.

    @ OP, is there any reason why you swap between constants and variables? Do you know the difference and when each should be used properly?
    we're smiling but we're close to tears, even after all these years

  7. #17
    Join Date
    Dec 2006
    Location
    Swindon
    Posts
    3,299
    Tokens
    215
    Habbo
    dunko

    Latest Awards:

    Default

    Quote Originally Posted by MattFr View Post
    Your salt is dynamic based on a number that will never happen again? Good luck with that.
    and stored in the users row
    Cheers for the good luck.

  8. #18
    Join Date
    Nov 2008
    Location
    Cambridge, UK
    Posts
    901
    Tokens
    100

    Default

    Quote Originally Posted by Blob View Post
    Cheers for the good luck.
    But surely if your database is compromised, storing the salt with the user row makes it easier to run a dictionary attack. Your method of generating numbers seems to be crazy inefficient anyway, just use a random.
    we're smiling but we're close to tears, even after all these years

  9. #19
    Join Date
    Dec 2006
    Location
    Swindon
    Posts
    3,299
    Tokens
    215
    Habbo
    dunko

    Latest Awards:

    Default

    Quote Originally Posted by MattFr View Post
    But surely if your database is compromised, storing the salt with the user row makes it easier to run a dictionary attack. Your method of generating numbers seems to be crazy inefficient anyway, just use a random.
    Same with vBulletin though, they store a salt in the user database too.

    Not quite sure why I did it in the first place, I was talking to another developer at the time who told me how he does his.

  10. #20
    Join Date
    Nov 2008
    Location
    Cambridge, UK
    Posts
    901
    Tokens
    100

    Default

    Quote Originally Posted by Blob View Post
    Same with vBulletin though, they store a salt in the user database too.

    Not quite sure why I did it in the first place, I was talking to another developer at the time who told me how he does his.
    vBulletin coding isn't exactly amazing.
    we're smiling but we're close to tears, even after all these years

Page 2 of 4 FirstFirst 1234 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •