dskyx46424 2013-11-16 11:34
浏览 33
已采纳

密码的安全哈希生成[重复]

This question already has an answer here:

Is it possible to get password from hash produced by following function by any method?

$salt is random 128 characters alpha numeric string.

function Get_Hash($pwd, $salt)
        {
            if ( CRYPT_BLOWFISH == 1) 
            {
                $pwd = hash("sha512",$pwd);
                $cost = "07";
                $hash = crypt($pwd, '$2a$' . $cost . '$' . $salt);
                return $hash;
            } 
            else  
            {
                $pwd = hash("sha512",$pwd);
                $hash = crypt($pwd, '$1$' . $salt . '$');
                return $hash;
            }
        }

There is already basic level brute force protection, system locked for 3-5 minutes after 3 failed attempts.

Is this good hashing function for small level application?

Thanks for your help.

</div>
  • 写回答

1条回答 默认 最新

  • dozr13344 2013-11-16 12:08
    关注

    Don't create your own hashing.

    PHP version 5.5 has some very nice and easy to use password hashing functions, and there is a library that backports them as far as to PHP 5.3.

    Include it, use it. Done.

    Download here https://github.com/ircmaxell/password_compat or include via Composer:

    "require":{
        "ircmaxell/password-compat":"~1.0"
    }
    
    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 c语言怎么用printf(“\b \b”)与getch()实现黑框里写入与删除?
  • ¥20 怎么用dlib库的算法识别小麦病虫害
  • ¥15 华为ensp模拟器中S5700交换机在配置过程中老是反复重启
  • ¥15 java写代码遇到问题,求帮助
  • ¥15 uniapp uview http 如何实现统一的请求异常信息提示?
  • ¥15 有了解d3和topogram.js库的吗?有偿请教
  • ¥100 任意维数的K均值聚类
  • ¥15 stamps做sbas-insar,时序沉降图怎么画
  • ¥15 买了个传感器,根据商家发的代码和步骤使用但是代码报错了不会改,有没有人可以看看
  • ¥15 关于#Java#的问题,如何解决?