|
Drupal 7 hashes
|
|
07-13-2012, 07:57 PM
Post: #1
|
|||
|
|||
|
Drupal 7 hashes
Hello everyone!
I'm performing a pentest and was able to compromise a web application via SQLi. This database server was also being used for Drupal. The latest version, 7 changed their hashing algorithm to SHA512 using this function: http://api.drupal.org/api/drupal/include...password/7 I don't see support for Drupal 7 specifically, but I'm wondering if the generic sha512 support would work. I'd normally just set up an instance of drupal and try but I'm not infront of my GPU machine.... |
|||
|
07-13-2012, 11:04 PM
Post: #2
|
|||
|
|||
|
RE: Drupal 7 hashes
Generic sha512 won't work.
|
|||
|
07-17-2012, 05:00 PM
Post: #3
|
|||
|
|||
| RE: Drupal 7 hashes | |||
|
07-17-2012, 06:37 PM
Post: #4
|
|||
|
|||
|
RE: Drupal 7 hashes
It looks like 15 rounds of SHA512, prefixed with '$S$<base64 encoded number of rounds><6byte random salt>'.
|
|||
|
07-19-2012, 08:08 AM
Post: #5
|
|||
|
|||
| RE: Drupal 7 hashes | |||
|
« Next Oldest | Next Newest »
|
Search
Member List
Calendar
Help



