Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #15301 > unrolled thread

Article: PHP Hash Comparison Weakness A Threat To Websites, Researcher Says

Started byuser1 <none@none.invalid>
First post2015-05-10 20:29 +0100
Last post2015-05-11 22:54 +0100
Articles 8 — 4 participants

Back to article view | Back to comp.lang.php


Contents

  Article: PHP Hash Comparison Weakness A Threat To Websites, Researcher Says user1 <none@none.invalid> - 2015-05-10 20:29 +0100
    Re: Article: PHP Hash Comparison Weakness A Threat To Websites, Researcher Says Jerry Stuckle <jstucklex@attglobal.net> - 2015-05-10 17:55 -0400
      Re: Article: PHP Hash Comparison Weakness A Threat To Websites, Researcher Says user1 <none@none.invalid> - 2015-05-10 23:23 +0100
        Re: Article: PHP Hash Comparison Weakness A Threat To Websites, Researcher Says Jerry Stuckle <jstucklex@attglobal.net> - 2015-05-10 18:46 -0400
          Re: Article: PHP Hash Comparison Weakness A Threat To Websites, Researcher Says user1 <none@none.invalid> - 2015-05-11 22:49 +0100
        Re: Article: PHP Hash Comparison Weakness A Threat To Websites, Researcher Says Jim Higgins <ILikeMy@Privacy.invalid> - 2015-05-11 19:53 +0000
          Re: Article: PHP Hash Comparison Weakness A Threat To Websites, Researcher Says "Christoph M. Becker" <cmbecker69@arcor.de> - 2015-05-11 23:06 +0200
            Re: Article: PHP Hash Comparison Weakness A Threat To Websites, Researcher Says user1 <none@none.invalid> - 2015-05-11 22:54 +0100

#15301 — Article: PHP Hash Comparison Weakness A Threat To Websites, Researcher Says

Fromuser1 <none@none.invalid>
Date2015-05-10 20:29 +0100
SubjectArticle: PHP Hash Comparison Weakness A Threat To Websites, Researcher Says
Message-ID<SOydnYeYVLkaLNLInZ2dnUU78VcAAAAA@giganews.com>
PHP Hash Comparison Weakness A Threat To Websites, Researcher Says

"Flaw could allow attackers to compromise user accounts, WhiteHat 
Security's Robert Hansen -- aka 'RSnake' -- says in new finding on 
'Magic Hash' vulnerability. "

URL: 
http://www.darkreading.com/vulnerabilities---threats/php-hash-comparison-weakness-a-threat-to-websites-researcher-says-/d/d-id/1320353

[toc] | [next] | [standalone]


#15302

FromJerry Stuckle <jstucklex@attglobal.net>
Date2015-05-10 17:55 -0400
Message-ID<miok25$g1d$1@dont-email.me>
In reply to#15301
On 5/10/2015 3:29 PM, user1 wrote:
> PHP Hash Comparison Weakness A Threat To Websites, Researcher Says
> 
> "Flaw could allow attackers to compromise user accounts, WhiteHat
> Security's Robert Hansen -- aka 'RSnake' -- says in new finding on
> 'Magic Hash' vulnerability. "
> 
> URL:
> http://www.darkreading.com/vulnerabilities---threats/php-hash-comparison-weakness-a-threat-to-websites-researcher-says-/d/d-id/1320353
> 

Which is not a problem with using proper coding techniques.

-- 
==================
Remove the "x" from my email address
Jerry Stuckle
jstucklex@attglobal.net
==================

[toc] | [prev] | [next] | [standalone]


#15303

Fromuser1 <none@none.invalid>
Date2015-05-10 23:23 +0100
Message-ID<L7KdnUdJy934R9LInZ2dnUU78T-dnZ2d@giganews.com>
In reply to#15302
On 10/05/2015 22:55, Jerry Stuckle wrote:
> On 5/10/2015 3:29 PM, user1 wrote:
> > PHP Hash Comparison Weakness A Threat To Websites, Researcher Says
> >
> > "Flaw could allow attackers to compromise user accounts, WhiteHat
> > Security's Robert Hansen -- aka 'RSnake' -- says in new finding on
> > 'Magic Hash' vulnerability. "
> >
> > URL:
> > http://www.darkreading.com/vulnerabilities---threats/php-hash-comparison-weakness-a-threat-to-websites-researcher-says-/d/d-id/1320353
> >
>
> Which is not a problem with using proper coding techniques.

Indeed, a fair point good sir.

Hopefully everyone knows about using proper coding techniques.

But just in-case some don't, or are still at a learning stage- perhaps 
you could recommend a good website as a source of information on proper 
coding techniques?
(For PHP specifically or more broadly.)

Thanks

[toc] | [prev] | [next] | [standalone]


#15304

FromJerry Stuckle <jstucklex@attglobal.net>
Date2015-05-10 18:46 -0400
Message-ID<mion1d$tad$1@dont-email.me>
In reply to#15303
On 5/10/2015 6:23 PM, user1 wrote:
> On 10/05/2015 22:55, Jerry Stuckle wrote:
>> On 5/10/2015 3:29 PM, user1 wrote:
>> > PHP Hash Comparison Weakness A Threat To Websites, Researcher Says
>> >
>> > "Flaw could allow attackers to compromise user accounts, WhiteHat
>> > Security's Robert Hansen -- aka 'RSnake' -- says in new finding on
>> > 'Magic Hash' vulnerability. "
>> >
>> > URL:
>> >
>> http://www.darkreading.com/vulnerabilities---threats/php-hash-comparison-weakness-a-threat-to-websites-researcher-says-/d/d-id/1320353
>>
>> >
>>
>> Which is not a problem with using proper coding techniques.
> 
> Indeed, a fair point good sir.
> 
> Hopefully everyone knows about using proper coding techniques.
> 
> But just in-case some don't, or are still at a learning stage- perhaps
> you could recommend a good website as a source of information on proper
> coding techniques?
> (For PHP specifically or more broadly.)
> 
> Thanks

Proper coding techniques is a huge subject - and one you won't find on a
website - at least not a free one.  It's too much and takes a lot of
experience and training.

There may be some good books on it - I know there were several years
ago, but I haven't checked recently.  There may also be some paid
courses on the internet, but I've never checked them out.

-- 
==================
Remove the "x" from my email address
Jerry Stuckle
jstucklex@attglobal.net
==================

[toc] | [prev] | [next] | [standalone]


#15307

Fromuser1 <none@none.invalid>
Date2015-05-11 22:49 +0100
Message-ID<iZSdnWxtZ-1vvszInZ2dnUU78LOdnZ2d@giganews.com>
In reply to#15304
On 10/05/2015 23:46, Jerry Stuckle wrote:
> On 5/10/2015 6:23 PM, user1 wrote:
> > On 10/05/2015 22:55, Jerry Stuckle wrote:
> >> On 5/10/2015 3:29 PM, user1 wrote:
> >> > PHP Hash Comparison Weakness A Threat To Websites, Researcher Says
> >> >
> >> > "Flaw could allow attackers to compromise user accounts, WhiteHat
> >> > Security's Robert Hansen -- aka 'RSnake' -- says in new finding on
> >> > 'Magic Hash' vulnerability. "
> >> >
> >> > URL:
> >> >
> >> http://www.darkreading.com/vulnerabilities---threats/php-hash-comparison-weakness-a-threat-to-websites-researcher-says-/d/d-id/1320353
> >>
> >> >
> >>
> >> Which is not a problem with using proper coding techniques.
> >
> > Indeed, a fair point good sir.
> >
> > Hopefully everyone knows about using proper coding techniques.
> >
> > But just in-case some don't, or are still at a learning stage- perhaps
> > you could recommend a good website as a source of information on proper
> > coding techniques?
> > (For PHP specifically or more broadly.)
> >
> > Thanks
>
> Proper coding techniques is a huge subject - and one you won't find on a
> website - at least not a free one.  It's too much and takes a lot of
> experience and training.
>
> There may be some good books on it - I know there were several years
> ago, but I haven't checked recently.  There may also be some paid
> courses on the internet, but I've never checked them out.
>

Just in-case it is of any use to anyone following this thread, I found 
these sites/pages as a starting point for PHP proper coding techniques - 
just in case they are of interest to any PHP beginners following this 
thread.

  - PHP and HTML ( of course :) )
     http://us3.php.net/manual/en/faq.html.php

  - PHP: The Right Way.
     http://www.phptherightway.com/

  - Best coding practices
     http://en.wikipedia.org/wiki/Best_coding_practices

  - 30+ PHP Best Practices for Beginners
http://code.tutsplus.com/tutorials/30-php-best-practices-for-beginners--net-6194

Disclaimer: I'm not saying these are all excellent, but here is 
something as-opposed-to-nothing, for what it might be worth; to somebody 
who has the appropriate beginner-status and sincere interest in learning 
more.

I had a quick look at the PHP documentation for this first time in a 
while. I had somewhat forgotten how informative it can be.
     ( http://php.net/docs.php )

Thanks for your time.



[toc] | [prev] | [next] | [standalone]


#15305

FromJim Higgins <ILikeMy@Privacy.invalid>
Date2015-05-11 19:53 +0000
Message-ID<k222lapa6pu0dl511m59788njeqm12dh78@4ax.com>
In reply to#15303
On Sun, 10 May 2015 23:23:31 +0100, in
<L7KdnUdJy934R9LInZ2dnUU78T-dnZ2d@giganews.com>, user1
<none@none.invalid> wrote:

>On 10/05/2015 22:55, Jerry Stuckle wrote:
>> On 5/10/2015 3:29 PM, user1 wrote:
>> > PHP Hash Comparison Weakness A Threat To Websites, Researcher Says
>> >
>> > "Flaw could allow attackers to compromise user accounts, WhiteHat
>> > Security's Robert Hansen -- aka 'RSnake' -- says in new finding on
>> > 'Magic Hash' vulnerability. "
>> >
>> > URL:
>> > http://www.darkreading.com/vulnerabilities---threats/php-hash-comparison-weakness-a-threat-to-websites-researcher-says-/d/d-id/1320353
>> >
>>
>> Which is not a problem with using proper coding techniques.
>
>Indeed, a fair point good sir.
>
>Hopefully everyone knows about using proper coding techniques.
>
>But just in-case some don't, or are still at a learning stage- perhaps 
>you could recommend a good website as a source of information on proper 
>coding techniques?

The article seems to give you the proper technique to overcome this
issue. Just read it to the very end end.

[toc] | [prev] | [next] | [standalone]


#15306

From"Christoph M. Becker" <cmbecker69@arcor.de>
Date2015-05-11 23:06 +0200
Message-ID<mir5kd$i73$1@solani.org>
In reply to#15305
Jim Higgins wrote:

> On Sun, 10 May 2015 23:23:31 +0100, in
> <L7KdnUdJy934R9LInZ2dnUU78T-dnZ2d@giganews.com>, user1
> <none@none.invalid> wrote:
> 
>> On 10/05/2015 22:55, Jerry Stuckle wrote:
>>> On 5/10/2015 3:29 PM, user1 wrote:
>>>> PHP Hash Comparison Weakness A Threat To Websites, Researcher Says
>>>>
>>>> "Flaw could allow attackers to compromise user accounts, WhiteHat
>>>> Security's Robert Hansen -- aka 'RSnake' -- says in new finding on
>>>> 'Magic Hash' vulnerability. "
>>>>
>>>> URL:
>>>> http://www.darkreading.com/vulnerabilities---threats/php-hash-comparison-weakness-a-threat-to-websites-researcher-says-/d/d-id/1320353
>>>
>>> Which is not a problem with using proper coding techniques.
>>
>> Indeed, a fair point good sir.
>>
>> Hopefully everyone knows about using proper coding techniques.
>>
>> But just in-case some don't, or are still at a learning stage- perhaps 
>> you could recommend a good website as a source of information on proper 
>> coding techniques?
> 
> The article seems to give you the proper technique to overcome this
> issue. Just read it to the very end end.

Indeed, using === resp. !== would help to solve this issue, but it still
wouldn't secure against potential timing attacks.  Therefore one should
use hash_equals() or a respective userland implementation for PHP
versions before 5.6.0, or maybe preferably the password hashing
functions[1] introduced in PHP 5.5.0 (or a respective fallback).

[1] <http://php.net/manual/en/ref.password.php>

-- 
Christoph M. Becker

[toc] | [prev] | [next] | [standalone]


#15308

Fromuser1 <none@none.invalid>
Date2015-05-11 22:54 +0100
Message-ID<iZSdnW9tZ-2SuMzInZ2dnUU78LOdnZ2d@giganews.com>
In reply to#15306
On 11/05/2015 22:06, Christoph M. Becker wrote:
> Indeed, using === resp. !== would help to solve this issue, but it still
> wouldn't secure against potential timing attacks.  Therefore one should
> use hash_equals() or a respective userland implementation for PHP
> versions before 5.6.0, or maybe preferably the password hashing
> functions[1] introduced in PHP 5.5.0 (or a respective fallback).
>
> [1] <http://php.net/manual/en/ref.password.php>
>

Good reading - I am grateful for the pointer, thank-you.

[toc] | [prev] | [standalone]


Back to top | Article view | comp.lang.php


csiph-web