SA-MP Forums Archive
Whirlpool being cracked. - Printable Version

+- SA-MP Forums Archive (https://sampforum.blast.hk)
+-- Forum: SA-MP (https://sampforum.blast.hk/forumdisplay.php?fid=3)
+--- Forum: General (https://sampforum.blast.hk/forumdisplay.php?fid=13)
+--- Thread: Whirlpool being cracked. (/showthread.php?tid=432584)

Pages: 1 2


Re: Whirlpool being cracked. - Y_Less - 23.04.2013

There are tutorials on salting and running an encryption multiple times - go read them.


Re: Whirlpool being cracked. - Coltmaster - 23.04.2013

You have to take practicality into it. Sure it can be cracked in theory, but strong encryptions can take hundreds of years to crack, at least with current technology.


Re: Whirlpool being cracked. - Kontrol - 24.04.2013

Thanks for the replys guys, im looking into salting them now.


Re: Whirlpool being cracked. - Kontrol - 24.04.2013

Salt added. thanks guys


Re: Whirlpool being cracked. - Riddy - 24.04.2013

Wow, thanks for the heads up. I got a bunch of scripts not using salt, nevermind whirlpool.


Re: Whirlpool being cracked. - Y_Less - 24.04.2013

And this is why I'm constantly telling people NOT to write their own user systems - getting them right is hard and vitally important. Any other system you can bodge together with bugs, user systems you have to really know what you're on about (and I don't claim to be - I've had to update y_users multiple times with more security).


Re: Whirlpool being cracked. - Y_Less - 24.04.2013

Has anyone here actually mentioned multiple rounds yet? Many hash systems now work by taking a password, salting it, encrypting it, then hashing the hash several THOUSAND times (with salts at different stages for good measure). This is so that the hash takes a noticeable amount of time to complete, thus making brute-force crack intractable (would take longer than any reasonable time available). If your hash system takes half a second and the user got the right password that's fine, but if you're trying to crack the password and have to run 1,000,000,000 attempts, that's nearly 16 years!

Also, how many people here blank the memory the plain-text password was stored in?


Re: Whirlpool being cracked. - KiNG3 - 24.04.2013

How do I salt my Whirlpool passwords? Can anyone help me with that?


Re: Whirlpool being cracked. - Y_Less - 24.04.2013

Quote:
Originally Posted by KiNG3
View Post
How do I salt my Whirlpool passwords? Can anyone help me with that?
Sure:

Quote:
Originally Posted by Y_Less
View Post
And this is why I'm constantly telling people NOT to write their own user systems - getting them right is hard and vitally important. Any other system you can bodge together with bugs, user systems you have to really know what you're on about (and I don't claim to be - I've had to update y_users multiple times with more security).



Re: Whirlpool being cracked. - KiNG3 - 24.04.2013

That doesn't, exactly explain to me HOW to salt the passwords.