Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.php > #15301 > unrolled thread
| Started by | user1 <none@none.invalid> |
|---|---|
| First post | 2015-05-10 20:29 +0100 |
| Last post | 2015-05-11 22:54 +0100 |
| Articles | 8 — 4 participants |
Back to article view | Back to comp.lang.php
Article: PHP Hash Comparison Weakness A Threat To Websites, Researcher Says user1 <none@none.invalid> - 2015-05-10 20:29 +0100
Re: Article: PHP Hash Comparison Weakness A Threat To Websites, Researcher Says Jerry Stuckle <jstucklex@attglobal.net> - 2015-05-10 17:55 -0400
Re: Article: PHP Hash Comparison Weakness A Threat To Websites, Researcher Says user1 <none@none.invalid> - 2015-05-10 23:23 +0100
Re: Article: PHP Hash Comparison Weakness A Threat To Websites, Researcher Says Jerry Stuckle <jstucklex@attglobal.net> - 2015-05-10 18:46 -0400
Re: Article: PHP Hash Comparison Weakness A Threat To Websites, Researcher Says user1 <none@none.invalid> - 2015-05-11 22:49 +0100
Re: Article: PHP Hash Comparison Weakness A Threat To Websites, Researcher Says Jim Higgins <ILikeMy@Privacy.invalid> - 2015-05-11 19:53 +0000
Re: Article: PHP Hash Comparison Weakness A Threat To Websites, Researcher Says "Christoph M. Becker" <cmbecker69@arcor.de> - 2015-05-11 23:06 +0200
Re: Article: PHP Hash Comparison Weakness A Threat To Websites, Researcher Says user1 <none@none.invalid> - 2015-05-11 22:54 +0100
| From | user1 <none@none.invalid> |
|---|---|
| Date | 2015-05-10 20:29 +0100 |
| Subject | Article: PHP Hash Comparison Weakness A Threat To Websites, Researcher Says |
| Message-ID | <SOydnYeYVLkaLNLInZ2dnUU78VcAAAAA@giganews.com> |
PHP Hash Comparison Weakness A Threat To Websites, Researcher Says "Flaw could allow attackers to compromise user accounts, WhiteHat Security's Robert Hansen -- aka 'RSnake' -- says in new finding on 'Magic Hash' vulnerability. " URL: http://www.darkreading.com/vulnerabilities---threats/php-hash-comparison-weakness-a-threat-to-websites-researcher-says-/d/d-id/1320353
[toc] | [next] | [standalone]
| From | Jerry Stuckle <jstucklex@attglobal.net> |
|---|---|
| Date | 2015-05-10 17:55 -0400 |
| Message-ID | <miok25$g1d$1@dont-email.me> |
| In reply to | #15301 |
On 5/10/2015 3:29 PM, user1 wrote: > PHP Hash Comparison Weakness A Threat To Websites, Researcher Says > > "Flaw could allow attackers to compromise user accounts, WhiteHat > Security's Robert Hansen -- aka 'RSnake' -- says in new finding on > 'Magic Hash' vulnerability. " > > URL: > http://www.darkreading.com/vulnerabilities---threats/php-hash-comparison-weakness-a-threat-to-websites-researcher-says-/d/d-id/1320353 > Which is not a problem with using proper coding techniques. -- ================== Remove the "x" from my email address Jerry Stuckle jstucklex@attglobal.net ==================
[toc] | [prev] | [next] | [standalone]
| From | user1 <none@none.invalid> |
|---|---|
| Date | 2015-05-10 23:23 +0100 |
| Message-ID | <L7KdnUdJy934R9LInZ2dnUU78T-dnZ2d@giganews.com> |
| In reply to | #15302 |
On 10/05/2015 22:55, Jerry Stuckle wrote: > On 5/10/2015 3:29 PM, user1 wrote: > > PHP Hash Comparison Weakness A Threat To Websites, Researcher Says > > > > "Flaw could allow attackers to compromise user accounts, WhiteHat > > Security's Robert Hansen -- aka 'RSnake' -- says in new finding on > > 'Magic Hash' vulnerability. " > > > > URL: > > http://www.darkreading.com/vulnerabilities---threats/php-hash-comparison-weakness-a-threat-to-websites-researcher-says-/d/d-id/1320353 > > > > Which is not a problem with using proper coding techniques. Indeed, a fair point good sir. Hopefully everyone knows about using proper coding techniques. But just in-case some don't, or are still at a learning stage- perhaps you could recommend a good website as a source of information on proper coding techniques? (For PHP specifically or more broadly.) Thanks
[toc] | [prev] | [next] | [standalone]
| From | Jerry Stuckle <jstucklex@attglobal.net> |
|---|---|
| Date | 2015-05-10 18:46 -0400 |
| Message-ID | <mion1d$tad$1@dont-email.me> |
| In reply to | #15303 |
On 5/10/2015 6:23 PM, user1 wrote: > On 10/05/2015 22:55, Jerry Stuckle wrote: >> On 5/10/2015 3:29 PM, user1 wrote: >> > PHP Hash Comparison Weakness A Threat To Websites, Researcher Says >> > >> > "Flaw could allow attackers to compromise user accounts, WhiteHat >> > Security's Robert Hansen -- aka 'RSnake' -- says in new finding on >> > 'Magic Hash' vulnerability. " >> > >> > URL: >> > >> http://www.darkreading.com/vulnerabilities---threats/php-hash-comparison-weakness-a-threat-to-websites-researcher-says-/d/d-id/1320353 >> >> > >> >> Which is not a problem with using proper coding techniques. > > Indeed, a fair point good sir. > > Hopefully everyone knows about using proper coding techniques. > > But just in-case some don't, or are still at a learning stage- perhaps > you could recommend a good website as a source of information on proper > coding techniques? > (For PHP specifically or more broadly.) > > Thanks Proper coding techniques is a huge subject - and one you won't find on a website - at least not a free one. It's too much and takes a lot of experience and training. There may be some good books on it - I know there were several years ago, but I haven't checked recently. There may also be some paid courses on the internet, but I've never checked them out. -- ================== Remove the "x" from my email address Jerry Stuckle jstucklex@attglobal.net ==================
[toc] | [prev] | [next] | [standalone]
| From | user1 <none@none.invalid> |
|---|---|
| Date | 2015-05-11 22:49 +0100 |
| Message-ID | <iZSdnWxtZ-1vvszInZ2dnUU78LOdnZ2d@giganews.com> |
| In reply to | #15304 |
On 10/05/2015 23:46, Jerry Stuckle wrote:
> On 5/10/2015 6:23 PM, user1 wrote:
> > On 10/05/2015 22:55, Jerry Stuckle wrote:
> >> On 5/10/2015 3:29 PM, user1 wrote:
> >> > PHP Hash Comparison Weakness A Threat To Websites, Researcher Says
> >> >
> >> > "Flaw could allow attackers to compromise user accounts, WhiteHat
> >> > Security's Robert Hansen -- aka 'RSnake' -- says in new finding on
> >> > 'Magic Hash' vulnerability. "
> >> >
> >> > URL:
> >> >
> >> http://www.darkreading.com/vulnerabilities---threats/php-hash-comparison-weakness-a-threat-to-websites-researcher-says-/d/d-id/1320353
> >>
> >> >
> >>
> >> Which is not a problem with using proper coding techniques.
> >
> > Indeed, a fair point good sir.
> >
> > Hopefully everyone knows about using proper coding techniques.
> >
> > But just in-case some don't, or are still at a learning stage- perhaps
> > you could recommend a good website as a source of information on proper
> > coding techniques?
> > (For PHP specifically or more broadly.)
> >
> > Thanks
>
> Proper coding techniques is a huge subject - and one you won't find on a
> website - at least not a free one. It's too much and takes a lot of
> experience and training.
>
> There may be some good books on it - I know there were several years
> ago, but I haven't checked recently. There may also be some paid
> courses on the internet, but I've never checked them out.
>
Just in-case it is of any use to anyone following this thread, I found
these sites/pages as a starting point for PHP proper coding techniques -
just in case they are of interest to any PHP beginners following this
thread.
- PHP and HTML ( of course :) )
http://us3.php.net/manual/en/faq.html.php
- PHP: The Right Way.
http://www.phptherightway.com/
- Best coding practices
http://en.wikipedia.org/wiki/Best_coding_practices
- 30+ PHP Best Practices for Beginners
http://code.tutsplus.com/tutorials/30-php-best-practices-for-beginners--net-6194
Disclaimer: I'm not saying these are all excellent, but here is
something as-opposed-to-nothing, for what it might be worth; to somebody
who has the appropriate beginner-status and sincere interest in learning
more.
I had a quick look at the PHP documentation for this first time in a
while. I had somewhat forgotten how informative it can be.
( http://php.net/docs.php )
Thanks for your time.
[toc] | [prev] | [next] | [standalone]
| From | Jim Higgins <ILikeMy@Privacy.invalid> |
|---|---|
| Date | 2015-05-11 19:53 +0000 |
| Message-ID | <k222lapa6pu0dl511m59788njeqm12dh78@4ax.com> |
| In reply to | #15303 |
On Sun, 10 May 2015 23:23:31 +0100, in <L7KdnUdJy934R9LInZ2dnUU78T-dnZ2d@giganews.com>, user1 <none@none.invalid> wrote: >On 10/05/2015 22:55, Jerry Stuckle wrote: >> On 5/10/2015 3:29 PM, user1 wrote: >> > PHP Hash Comparison Weakness A Threat To Websites, Researcher Says >> > >> > "Flaw could allow attackers to compromise user accounts, WhiteHat >> > Security's Robert Hansen -- aka 'RSnake' -- says in new finding on >> > 'Magic Hash' vulnerability. " >> > >> > URL: >> > http://www.darkreading.com/vulnerabilities---threats/php-hash-comparison-weakness-a-threat-to-websites-researcher-says-/d/d-id/1320353 >> > >> >> Which is not a problem with using proper coding techniques. > >Indeed, a fair point good sir. > >Hopefully everyone knows about using proper coding techniques. > >But just in-case some don't, or are still at a learning stage- perhaps >you could recommend a good website as a source of information on proper >coding techniques? The article seems to give you the proper technique to overcome this issue. Just read it to the very end end.
[toc] | [prev] | [next] | [standalone]
| From | "Christoph M. Becker" <cmbecker69@arcor.de> |
|---|---|
| Date | 2015-05-11 23:06 +0200 |
| Message-ID | <mir5kd$i73$1@solani.org> |
| In reply to | #15305 |
Jim Higgins wrote: > On Sun, 10 May 2015 23:23:31 +0100, in > <L7KdnUdJy934R9LInZ2dnUU78T-dnZ2d@giganews.com>, user1 > <none@none.invalid> wrote: > >> On 10/05/2015 22:55, Jerry Stuckle wrote: >>> On 5/10/2015 3:29 PM, user1 wrote: >>>> PHP Hash Comparison Weakness A Threat To Websites, Researcher Says >>>> >>>> "Flaw could allow attackers to compromise user accounts, WhiteHat >>>> Security's Robert Hansen -- aka 'RSnake' -- says in new finding on >>>> 'Magic Hash' vulnerability. " >>>> >>>> URL: >>>> http://www.darkreading.com/vulnerabilities---threats/php-hash-comparison-weakness-a-threat-to-websites-researcher-says-/d/d-id/1320353 >>> >>> Which is not a problem with using proper coding techniques. >> >> Indeed, a fair point good sir. >> >> Hopefully everyone knows about using proper coding techniques. >> >> But just in-case some don't, or are still at a learning stage- perhaps >> you could recommend a good website as a source of information on proper >> coding techniques? > > The article seems to give you the proper technique to overcome this > issue. Just read it to the very end end. Indeed, using === resp. !== would help to solve this issue, but it still wouldn't secure against potential timing attacks. Therefore one should use hash_equals() or a respective userland implementation for PHP versions before 5.6.0, or maybe preferably the password hashing functions[1] introduced in PHP 5.5.0 (or a respective fallback). [1] <http://php.net/manual/en/ref.password.php> -- Christoph M. Becker
[toc] | [prev] | [next] | [standalone]
| From | user1 <none@none.invalid> |
|---|---|
| Date | 2015-05-11 22:54 +0100 |
| Message-ID | <iZSdnW9tZ-2SuMzInZ2dnUU78LOdnZ2d@giganews.com> |
| In reply to | #15306 |
On 11/05/2015 22:06, Christoph M. Becker wrote: > Indeed, using === resp. !== would help to solve this issue, but it still > wouldn't secure against potential timing attacks. Therefore one should > use hash_equals() or a respective userland implementation for PHP > versions before 5.6.0, or maybe preferably the password hashing > functions[1] introduced in PHP 5.5.0 (or a respective fallback). > > [1] <http://php.net/manual/en/ref.password.php> > Good reading - I am grateful for the pointer, thank-you.
[toc] | [prev] | [standalone]
Back to top | Article view | comp.lang.php
csiph-web