Password Hashing in PHP
Sign in to YouTube
Sign in to YouTube
Sign in to YouTube
Published on Oct 8, 2012
An unconference talk that I gave at the PHP North West 2012 conference.
It explores the ways that password hashes are attacked, and how those attacks can be prevented. It also goes into some tools that are available to properly hash passwords for storage in PHP. We introduce the new Password Hashing API that will be available in PHP 5.5...
Slides: http://ircmaxell.github.com/password-...
References:
PHP 5.5 Password Hashing: https://wiki.php.net/rfc/password_hash
Password Compat: https://github.com/ircmaxell/password...
PasswordLib: https://github.com/ircmaxell/PHP-Pass...
PHPASS: http://www.openwall.com/phpass/
Tools:
John The Ripper: http://www.openwall.com/john/
HashCat: http://hashcat.net/
-
Category
-
License
Creative Commons Attribution license (reuse allowed)
Loading...
Loading...
Loading...
Loading...
Loading...
-
5:43
Don't encrypt passwordsby J4vv4DFeatured
11,963
-
1:18:35
SHA-1 Hash Functionby Kiran Kuppa
968 views
-
49:04
PHP Programming Part 6: Printing to Files with PHPby Eli the Computer Guy
18,624 views
-
58:38
Lessons Learned Integrating Drupal with nodejsmongodb Powered Webservices [May 17, 2012]by Acquia
784 views
-
10:54
Hashingby davefeinberg
19,555 views
-
39:22
PHP Programming Part 1: Introduction to PHP Programmingby Eli the Computer Guy
87,183 views
-
44:48
Dan Ingalls: Object-Oriented Programmingby ESUG
916 views
-
6:02
Programming With Anthony - References In PHPby Anthony Ferrara
1,983 views
-
51:25
Getting Started with Google Compute Engineby GoogleDevelopers
3,332 views
-
2:51
How To Use John The Ripper To Crack Passwords-BackTrack Tutorials For Beginners - Learn With Pranshuby Free Hacking Tutorials - Learn With Pranshu
4,625 views
-
11:11
PHP Tutorial: Password Encryption with MD5, SHA1, and Crypt -HD-by RiverCityGraphix
7,873 views
-
7:39
Programming With Anthony - Encryptionby Anthony Ferrara
1,969 views
-
41:20
PHP Programming Part 4: Variables in Print in PHP Programmingby Eli the Computer Guy
21,393 views
-
28:37
I Forgot Your Password: Randomness Attacks Against PHP Applicationsby SecurityTubeCons
657 views
-
5:52
THOR 5000 - The ultimate Can-Crusher (Dosenpresse)by Eresus1
37,136 views
-
3:57
Cracking hashed passwords with John the Ripper and UNIQPASSby aselya2600
5,431 views
-
5:22
Failure Is Always An Option - Programming With Anthonyby Anthony Ferrara
951 views
-
3:01
A Look Back on PHP 5.5 Development in 2012by Sherif Ramadan
1,069 views
-
29:03
Object-Oriented Programmingby Brian Will
11,730 views
-
3:26
JavaScript Closures - Programming With Anthonyby Anthony Ferrara
2,814 views
- Loading more suggestions...
Uploader Comments (Anthony Ferrara)
Anthony Ferrara 7 months ago
FYI: the bcrypt crack that was shown in the demo finally finished. In a grand total of 15 days 9 hours 24 minutes. To crack what MD5 cracked in 15 seconds... :-D
Sign in to YouTube
Sign in to YouTube
Top Comments
brandonb927 7 months ago
Awesome video! Going to be showing a portion of this in a presentation to some university students as an alumni
Sign in to YouTube
Sign in to YouTube
All Comments (15)
Henry Rafeh 2 months ago
wow i didnt understand shit so confusing nube to this
Sign in to YouTube
Sign in to YouTube
Aaron Fisher 2 months ago
Why is this still a thing, just because you use a Mac or Windows or whatever you use does not change your ability.
Sign in to YouTube
Sign in to YouTube
Wesley Murch 3 months ago
I've always called it "PH Pass" (as in PASSword), but I there's something I like about about the way you say "PHP Ass".
Sign in to YouTube
Sign in to YouTube
gamer9774 3 months ago
mac user? * immediately clicks back button*
Sign in to YouTube
Sign in to YouTube
Kparris7 4 months ago
Thanks for the video man!
Sign in to YouTube
Sign in to YouTube
Thomas Maurstad Larsson 6 months ago
Awesome talk.
Sign in to YouTube
Sign in to YouTube
Bruno Cassol 7 months ago
Awesome! Thank you for sharing!
Sign in to YouTube
Sign in to YouTube