Forum

how password are en...
 
Notifications
Retirer tout

how password are encrypted

7 Posts
4 Utilisateurs
0 Reactions
8,321 Vu
(@sogeti)
Posts: 135
Estimable Member
Début du sujet
 
[#6090]

Hi,

Im searching how password are encrypted in the table [resource], column [password] in projeqtor database (mh5, sh256..)

Could you help me ?

Benjamin


 
Posté : 25/06/2019 11:45 am
(@babynus)
Posts: 14952
Membre Admin
 

They are encrypted in a non bijective way : you cannot decrypt passwords.
To check password, we encrypt password given by user with same method and compare result with stored encrypted value (it is same process as for credit card code)


 
Posté : 25/06/2019 1:58 pm
(@sogeti)
Posts: 135
Estimable Member
Début du sujet
 

Thanks for your reply.
For explication : We want to create a new application using informations in the report view (work planned, work imputed...) and use the login/password in the projeqtor database
This is why we want to use the same encryption method.


 
Posté : 25/06/2019 3:59 pm
Paul Ghobril
(@envergus)
Posts: 46
Trusted Member
 

MD5


 
Posté : 25/06/2019 5:46 pm
(@babynus)
Posts: 14952
Membre Admin
 

MD5

No, not so easy.
it is sha256 encryption of password with extra "salt" (randow key stored on user to reduce brute force attacks efficiency)

$this->password=hash('sha256',$paramDefaultPassword.$this->salt);


 
Posté : 25/06/2019 6:24 pm
(@gohrner)
Posts: 74
Estimable Member
 

How about a future switch to the secure password hashing and verification functions PHP now offers?

https://secure.php.net/manual/en/function.password-hash.php https://secure.php.net/manual/en/function.password-verify.php

This will be significantly more secure, as sha256 hashes are comparatively quickly computed using modern graphics cards, allowing to break even non-trivial salted passwords just by brute-forcing them.


 
Posté : 26/06/2019 1:44 am
(@babynus)
Posts: 14952
Membre Admin
 

Is there really any interest ?
We are dealing with Project Management Tool, not NSA nor Bank, nor credit card. 👿
Moreover, the passwords are stored in the DB, so best security will be to protect your DB access 😉
And you can also switch to LDAP authentication, or, since V8.1, SSO SAML authentication.


 
Posté : 26/06/2019 1:51 am
Share:
Retour en haut