<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Hack the Password !!!</title>
	<atom:link href="http://www.sajithmr.me/hack-the-password/feed" rel="self" type="application/rss+xml" />
	<link>http://www.sajithmr.me/hack-the-password</link>
	<description></description>
	<lastBuildDate>Fri, 27 Jan 2012 16:09:46 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: ford</title>
		<link>http://www.sajithmr.me/hack-the-password/comment-page-1#comment-103826</link>
		<dc:creator>ford</dc:creator>
		<pubDate>Wed, 21 Apr 2010 06:50:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.sajithmr.com/hack-the-password/#comment-103826</guid>
		<description>Hi. EMAIL ME!!! I&#039;m hacker. Can get you a myspace, facebook,yahoo,msn/hotmail, gmail, aol...etc password. I do charge money though,but will show proof i have it.  Are you interested?  please email me at fordtrucks90@live.com      (I was formly known as fordf202006 on yahoo but my account was deleted)</description>
		<content:encoded><![CDATA[<p>Hi. EMAIL ME!!! I&#8217;m hacker. Can get you a myspace, facebook,yahoo,msn/hotmail, gmail, aol&#8230;etc password. I do charge money though,but will show proof i have it.  Are you interested?  please email me at <a href="mailto:fordtrucks90@live.com">fordtrucks90@live.com</a>      (I was formly known as fordf202006 on yahoo but my account was deleted)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Frank</title>
		<link>http://www.sajithmr.me/hack-the-password/comment-page-1#comment-103723</link>
		<dc:creator>Frank</dc:creator>
		<pubDate>Tue, 20 Apr 2010 15:09:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.sajithmr.com/hack-the-password/#comment-103723</guid>
		<description>Good article! Thanks a lot.</description>
		<content:encoded><![CDATA[<p>Good article! Thanks a lot.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Omkar Khair</title>
		<link>http://www.sajithmr.me/hack-the-password/comment-page-1#comment-99336</link>
		<dc:creator>Omkar Khair</dc:creator>
		<pubDate>Sun, 21 Mar 2010 06:37:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.sajithmr.com/hack-the-password/#comment-99336</guid>
		<description>Absence of salt would store the plain hashed password in the table. As mentioned in the post, if the table is extracted some how then the intruder can find a match for his hash.

The chances of this happening is considerably low, but adding Salt would make a significant improvement in security.</description>
		<content:encoded><![CDATA[<p>Absence of salt would store the plain hashed password in the table. As mentioned in the post, if the table is extracted some how then the intruder can find a match for his hash.</p>
<p>The chances of this happening is considerably low, but adding Salt would make a significant improvement in security.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: summary</title>
		<link>http://www.sajithmr.me/hack-the-password/comment-page-1#comment-81037</link>
		<dc:creator>summary</dc:creator>
		<pubDate>Wed, 26 Aug 2009 09:47:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.sajithmr.com/hack-the-password/#comment-81037</guid>
		<description>What if Salt value is not added to DB table ?</description>
		<content:encoded><![CDATA[<p>What if Salt value is not added to DB table ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chetan</title>
		<link>http://www.sajithmr.me/hack-the-password/comment-page-1#comment-31863</link>
		<dc:creator>Chetan</dc:creator>
		<pubDate>Sun, 30 Nov 2008 11:22:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.sajithmr.com/hack-the-password/#comment-31863</guid>
		<description>Currently databases are the most targeted objects by hackers, it is really important to keep them safe.</description>
		<content:encoded><![CDATA[<p>Currently databases are the most targeted objects by hackers, it is really important to keep them safe.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ford</title>
		<link>http://www.sajithmr.me/hack-the-password/comment-page-1#comment-19697</link>
		<dc:creator>Ford</dc:creator>
		<pubDate>Mon, 18 Aug 2008 23:17:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.sajithmr.com/hack-the-password/#comment-19697</guid>
		<description>hi. I am a hacker. I can get you an aol,yahoo,myspace,facebook,gmail...etc password. I do charge a fee to get a password though. Once i do get password i&#039;ll show you proof i have it. Are you interested? E-mail me at Fordf202006@yahoo.com</description>
		<content:encoded><![CDATA[<p>hi. I am a hacker. I can get you an aol,yahoo,myspace,facebook,gmail&#8230;etc password. I do charge a fee to get a password though. Once i do get password i&#8217;ll show you proof i have it. Are you interested? E-mail me at <a href="mailto:Fordf202006@yahoo.com">Fordf202006@yahoo.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: peeto</title>
		<link>http://www.sajithmr.me/hack-the-password/comment-page-1#comment-10980</link>
		<dc:creator>peeto</dc:creator>
		<pubDate>Fri, 23 May 2008 00:40:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.sajithmr.com/hack-the-password/#comment-10980</guid>
		<description>select u.user from table as u where u.password=sha1(concat(&#039;access&#039;, u.salt, &#039;hackedglobalpattern&#039;));</description>
		<content:encoded><![CDATA[<p>select u.user from table as u where u.password=sha1(concat(&#8216;access&#8217;, u.salt, &#8216;hackedglobalpattern&#8217;));</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Babu Syed</title>
		<link>http://www.sajithmr.me/hack-the-password/comment-page-1#comment-6188</link>
		<dc:creator>Babu Syed</dc:creator>
		<pubDate>Wed, 19 Mar 2008 12:25:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.sajithmr.com/hack-the-password/#comment-6188</guid>
		<description>like the window showing the visitor&#039;s location in map. how can i get it for my page?
BS  at psbabusyed@gmail.com</description>
		<content:encoded><![CDATA[<p>like the window showing the visitor&#8217;s location in map. how can i get it for my page?<br />
BS  at <a href="mailto:psbabusyed@gmail.com">psbabusyed@gmail.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Binny V A</title>
		<link>http://www.sajithmr.me/hack-the-password/comment-page-1#comment-4939</link>
		<dc:creator>Binny V A</dc:creator>
		<pubDate>Tue, 04 Mar 2008 09:25:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.sajithmr.com/hack-the-password/#comment-4939</guid>
		<description>Great! Thanks for clearing that up</description>
		<content:encoded><![CDATA[<p>Great! Thanks for clearing that up</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sajith M.R</title>
		<link>http://www.sajithmr.me/hack-the-password/comment-page-1#comment-4865</link>
		<dc:creator>Sajith M.R</dc:creator>
		<pubDate>Mon, 03 Mar 2008 19:06:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.sajithmr.com/hack-the-password/#comment-4865</guid>
		<description>Hi Binny,
$md5_password was a mistake happened while copy-pasting .  I edited that in article now.  And about the checking in login, see below.

The salt is created by random, but you have to save this salt in another filed into your database table (that i mentioned in this article). So when login check, what you have to do is:
1) Get the saved salt from database table. (Select salt from table where username = &#039;Sanjay&#039;);

2) Recreate the hash from user entered password . say $password

3) Calculate the hash digest from the former formula. 
&lt;?php $hash_password = sha1($password . $salt . auth::GlobalPattern()); ?&gt;

4) Get the saved hash say $saved_hash from table (Select password from table where user=&#039;Sanjay&#039;);

5) Compare both. $hash_password and $saved_hash

6) If both are equal login, else invalid password. 

Thanks
Syth</description>
		<content:encoded><![CDATA[<p>Hi Binny,<br />
$md5_password was a mistake happened while copy-pasting .  I edited that in article now.  And about the checking in login, see below.</p>
<p>The salt is created by random, but you have to save this salt in another filed into your database table (that i mentioned in this article). So when login check, what you have to do is:<br />
1) Get the saved salt from database table. (Select salt from table where username = &#8216;Sanjay&#8217;);</p>
<p>2) Recreate the hash from user entered password . say $password</p>
<p>3) Calculate the hash digest from the former formula.<br />
< ?php $hash_password = sha1($password . $salt . auth::GlobalPattern()); ?></p>
<p>4) Get the saved hash say $saved_hash from table (Select password from table where user=&#8217;Sanjay&#8217;);</p>
<p>5) Compare both. $hash_password and $saved_hash</p>
<p>6) If both are equal login, else invalid password. </p>
<p>Thanks<br />
Syth</p>
]]></content:encoded>
	</item>
</channel>
</rss>

