[UberCMS] Password Hash Type

Results 1 to 15 of 15
  1. #1
    Valued Member cuperus is offline
    MemberRank
    Aug 2009 Join Date
    108Posts

    [UberCMS] Password Hash Type

    hello,

    I am going to release something soon but i need 1 awnser!
    What kinda HASH type is ubercms using with they passwords


  2. #2
    Member XenoGFX is offline
    MemberRank
    May 2010 Join Date
    97Posts

    Re: [UberCMS] Password Hash Type

    its a salted hash with sha1([salt].[password])

  3. #3
    Live Ocottish Sverlord Joopie is offline
    LegendRank
    Jun 2010 Join Date
    The NetherlandsLocation
    2,773Posts

    Re: [UberCMS] Password Hash Type

    How hard is't to look at the source :S

    Code:
    public function UberHash($input = '')
    	{
    		return sha1($input . $this->config['Site']['hash_secret']);
    	}

  4. #4
    Member pabiboy is offline
    MemberRank
    May 2009 Join Date
    HeavenLocation
    83Posts

    Re: [UberCMS] Password Hash Type

    Okay,But is it possible to make md5 for Manage folder?Because its sha1

  5. #5
    Proficient Member </Meap> is offline
    MemberRank
    Jul 2010 Join Date
    159Posts

    Re: [UberCMS] Password Hash Type

    its md5 encrypted with a sha1 hash

  6. #6
    Occasional Visitor Cecer is offline
    MemberRank
    Aug 2006 Join Date
    EnglandLocation
    743Posts

    Re: [UberCMS] Password Hash Type

    Quick lesson for the few people in this thread who seem to not understand hashing

    Hashing is NOT Encryption
    Hashing can't be decrypted... it is one way.
    Encryption can be decrypted.

    Hashing is more secure for things like passwords.

    MD5 is one hashing algorithm.
    SHA1 is a different hashing algorithm.

    MD5 is outdated and not as secure as SHA1.
    SHA1 is getting a little dated now.

    There are newer hashing algorithms such as SHA2 (which has multiple versions).

  7. #7
    Member pabiboy is offline
    MemberRank
    May 2009 Join Date
    HeavenLocation
    83Posts

    Re: [UberCMS] Password Hash Type

    Then Why doesn't it won't login me in manage (ubercms housekeeping) Says Invalid Details?But When I use SHA1 Hash It will let me.

  8. #8
    Valued Member cuperus is offline
    MemberRank
    Aug 2009 Join Date
    108Posts

    Re: [UberCMS] Password Hash Type

    Quote Originally Posted by pabiboy View Post
    Then Why doesn't it won't login me in manage (ubercms housekeeping) Says Invalid Details?But When I use SHA1 Hash It will let me.
    Need help?

  9. #9
    Account Upgraded | Title Enabled! jeroen262 is offline
    MemberRank
    Feb 2009 Join Date
    231Posts

    Re: [UberCMS] Password Hash Type

    Quote Originally Posted by cecer1 View Post
    [B][U]Quick lesson for the few people in
    Hashing can't be decrypted... it is one way.
    That's not true.
    You have to find out how the hash code works, but if you know that you can decrypt it.

  10. #10
    son, i am dissapoint Near is offline
    MemberRank
    Sep 2009 Join Date
    The NetherlandsLocation
    491Posts

    Re: [UberCMS] Password Hash Type

    It's one way like cecer says. You can only run hashes through rainbow tables to have a chance to find the plain text string. Authentication using hashes works like this:

    You compare the plain text input hash with the hashed string in the database by hashing the input. So, you're comparing the hashes. It's secure, but because of all the rainbow tables on the internet it's more secure to use a salt and a combination of sha1 and md5.

  11. #11
    Member XenoGFX is offline
    MemberRank
    May 2010 Join Date
    97Posts

    Re: [UberCMS] Password Hash Type

    Quote Originally Posted by cecer1 View Post
    Quick lesson for the few people in this thread who seem to not understand hashing

    Hashing is NOT Encryption
    Hashing can't be decrypted... it is one way.
    Encryption can be decrypted.

    Hashing is more secure for things like passwords.

    MD5 is one hashing algorithm.
    SHA1 is a different hashing algorithm.

    MD5 is outdated and not as secure as SHA1.
    SHA1 is getting a little dated now.

    There are newer hashing algorithms such as SHA2 (which has multiple versions).

    if you know this then you should know about rainbow tables ;)

  12. #12
    Account Upgraded | Title Enabled! Punk is offline
    MemberRank
    Dec 2008 Join Date
    VirginiaLocation
    892Posts

    Re: [UberCMS] Password Hash Type

    Quote Originally Posted by cecer1 View Post
    Quick lesson for the few people in this thread who seem to not understand hashing

    Hashing is NOT Encryption
    Hashing can't be decrypted... it is one way.
    Encryption can be decrypted.

    Hashing is more secure for things like passwords.

    MD5 is one hashing algorithm.
    SHA1 is a different hashing algorithm.

    MD5 is outdated and not as secure as SHA1.
    SHA1 is getting a little dated now.

    There are newer hashing algorithms such as SHA2 (which has multiple versions).
    Hashing can't be decrypted... it is one way.
    your incorrent on that ^

  13. #13
    Lurking since '06 1ntel is offline
    MemberRank
    Jul 2006 Join Date
    401Posts

    Re: [UberCMS] Password Hash Type

    Quote Originally Posted by OneEye View Post
    Hashing can't be decrypted... it is one way.
    your incorrent on that ^
    Actually you can't decrypt a hash, you can only go on based by Rainbow Tables, and even then it is impossible because the whole idea of using a Secret Key makes Rainbow Tables impossible.

    If hashs could be decrypted in a simple easy step, then it would make sense to save passwords unencrypted.

  14. #14
    Member XenoGFX is offline
    MemberRank
    May 2010 Join Date
    97Posts

    Re: [UberCMS] Password Hash Type

    Quote Originally Posted by matty13 View Post
    Actually you can't decrypt a hash, you can only go on based by Rainbow Tables, and even then it is impossible because the whole idea of using a Secret Key makes Rainbow Tables impossible.

    If hashs could be decrypted in a simple easy step, then it would make sense to save passwords unencrypted.
    not if you have the salt...you must have the salt to "decrypt" salted hashes...

  15. #15
    Valued Member trantium is offline
    MemberRank
    Jun 2007 Join Date
    103Posts

    Re: [UberCMS] Password Hash Type

    Can someone try to get the ubercms housekeeping working with a md5 hash?

    Thanks



Advertisement