Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le juin 14, 2012, 07:11:03

Titre: [Sophos]"One in 256 times *any* password might get you in" - MySQL authentication disaster
Posté par: igor51 le juin 14, 2012, 07:11:03
"One in 256 times *any* password might get you in" - MySQL authentication disaster

What if your authentication system itself were at fault? You could have the hardest-to-guess password, salted and hashed thousands of times, and still be at risk.

That's what happened to MySQL and MariaDB.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=nakedsecurity.sophos.com&blog=15254721&post=171391&subd=sophosnews&ref=&feed=1" width="1" height="1" /><img src="http://feeds.feedburner.com/~r/nakedsecurity/~4/Z3heiUQphFU" height="1" width="1"/>
Source: &quot;One in 256 times *any* password might get you in&quot; - MySQL authentication disaster (http://feedproxy.google.com/~r/nakedsecurity/~3/Z3heiUQphFU/)