hash algorithms - best method db sec

alexho

New Member
Reaction score
0
i'm likely going to be redoing the way i encrypt passwords in my database. this is in general, hiding data keeping it safe in your database.
more of web programming, but could be applied elsewhere using other functions - general cryptography.

hash algorithms md5, sha1, haval128 are weak alone.
whirlpool, tiger192, ripemd160 are the best hashes, if possible use them.

the slowest encrypting method is probably the best (in most cases) it will tend to be harder to crack via rainbow tables. use slower logins, session based fails etc.

do not use multiple hashes on a pasword it will reduce the possibilities. ex md5(sha1(md5((base64_encode($pass))))

generate a unique salt for each user. this will individualize the threat to single user therefore the attacker must generate a table for every user on your database, very tedious for them... use multiple salts in the password, and global salts as well.
Code:
function rand_gen($n) {
$rv=Array("a", "b", "c", "d", "e","f","g","h","i","j","k","l","n","o","p","-","_","%","@","!","0", "+", "*","~","$","#", "z", "m", "r", "x", "y", "q", "w", "p", "u", "s", "t", "g", "1", "2", "3", "4", "5", "6", "7", "8", "9");

$rvt=count($rv)-1;

for ($i=0;$i<$n;$i++) {
$constructedauth.=$rv[rand(0,$rvt)];
}
return $constructedauth;
}
$rand=rand_gen(50);

$hashish=str_split($hash,strlen($hash)/2);
$password = str_split($password,strlen($password)/2);
$convert_pass=hash('whirlpool',$oassword[0].$hashish[0].$password[1].$hashish[1]);

mysql --> users table `$convert_pass`, `$rand`

--->split data up in every which way, make it complex - cryptic.
-->use random salts in unique login sessions, store bits and pieces on the client in such a way that serves to fool/confuse/bewilder the attacker
->as for cookies to prevent theft throw in a client specific ip / user agent in with the password or in another chunk of data. that will stick it in the theifs pipe :)

maybe i put this in the wrong topic, anyway extrapolate on general cryptography, methods in c++ or other language

Any criticisms to this/or better possible methods you can think of that i may be missing?
 
General chit-chat
Help Users
  • No one is chatting at the moment.
  • WildTurkey WildTurkey:
    is there a stephen green in the house?
    +1
  • The Helper The Helper:
    What is up WildTurkey?
  • The Helper The Helper:
    Looks like Google fixed whatever mistake that made the recipes on the site go crazy and we are no longer trending towards a recipe site lol - I don't care though because it motivated me to spend alot of time on the site improving it and at least now the content people are looking at is not stupid and embarrassing like it was when I first got back into this like 5 years ago.
  • The Helper The Helper:
    Plus - I have a pretty bad ass recipe collection now! That section of the site is 10 thousand times better than it was before
  • The Helper The Helper:
    We now have a web designer at my job. A legit talented professional! I am going to get him to redesign the site theme. It is time.
  • Varine Varine:
    I got one more day of community service and then I'm free from this nonsense! I polished a cop car today for a funeral or something I guess
  • Varine Varine:
    They also were digging threw old shit at the sheriff's office and I tried to get them to give me the old electronic stuff, but they said no. They can't give it to people because they might use it to impersonate a cop or break into their network or some shit? idk but it was a shame to see them take a whole bunch of radios and shit to get shredded and landfilled
  • The Helper The Helper:
    whatever at least you are free
  • Monovertex Monovertex:
    How are you all? :D
    +1
  • Ghan Ghan:
    Howdy
  • Ghan Ghan:
    Still lurking
    +3
  • The Helper The Helper:
    I am great and it is fantastic to see you my friend!
    +1
  • The Helper The Helper:
    If you are new to the site please check out the Recipe and Food Forum https://www.thehelper.net/forums/recipes-and-food.220/
  • Monovertex Monovertex:
    How come you're so into recipes lately? Never saw this much interest in this topic in the old days of TH.net
  • Monovertex Monovertex:
    Hmm, how do I change my signature?
  • tom_mai78101 tom_mai78101:
    Signatures can be edit in your account profile. As for the old stuffs, I'm thinking it's because Blizzard is now under Microsoft, and because of Microsoft Xbox going the way it is, it's dreadful.
  • The Helper The Helper:
    I am not big on the recipes I am just promoting them - I use the site as a practice place promoting stuff
    +2
  • Monovertex Monovertex:
    @tom_mai78101 I must be blind. If I go on my profile I don't see any area to edit the signature; If I go to account details (settings) I don't see any signature area either.
  • The Helper The Helper:
    You can get there if you click the bell icon (alerts) and choose preferences from the bottom, signature will be in the menu on the left there https://www.thehelper.net/account/preferences
  • The Helper The Helper:
    I think I need to split the Sci/Tech news forum into 2 one for Science and one for Tech but I am hating all the moving of posts I would have to do
  • The Helper The Helper:
    What is up Old Mountain Shadow?

      The Helper Discord

      Members online

      Affiliates

      Hive Workshop NUON Dome World Editor Tutorials

      Network Sponsors

      Apex Steel Pipe - Buys and sells Steel Pipe.
      Top