<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://tcwiki.azurewebsites.net/index.php?action=history&amp;feed=atom&amp;title=Hashed_Password</id>
		<title>Hashed Password - Revision history</title>
		<link rel="self" type="application/atom+xml" href="http://tcwiki.azurewebsites.net/index.php?action=history&amp;feed=atom&amp;title=Hashed_Password"/>
		<link rel="alternate" type="text/html" href="http://tcwiki.azurewebsites.net/index.php?title=Hashed_Password&amp;action=history"/>
		<updated>2026-09-19T05:45:57Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.4</generator>

	<entry>
		<id>http://tcwiki.azurewebsites.net/index.php?title=Hashed_Password&amp;diff=16345&amp;oldid=prev</id>
		<title>Tom: /* Problem */</title>
		<link rel="alternate" type="text/html" href="http://tcwiki.azurewebsites.net/index.php?title=Hashed_Password&amp;diff=16345&amp;oldid=prev"/>
				<updated>2022-12-17T19:23:30Z</updated>
		
		<summary type="html">&lt;p&gt;‎&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Problem&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;' lang='en'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 19:23, 17 December 2022&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l10&quot; &gt;Line 10:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 10:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* If the password hash is taken from a provider, it can be used to sign-into that provider.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* If the password hash is taken from a provider, it can be used to sign-into that provider.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* In one well-known attack against air-gapped systems, many users had the same password in providers on both sides of the gap. So if (1) the password hash could be obtained in one side of the gap, and (2) the same AD hash was used on both sides of the gap, then anyone with privileged access on one side could access the other side using the same hash.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* In one well-known attack against air-gapped systems, many users had the same password in providers on both sides of the gap. So if (1) the password hash could be obtained in one side of the gap, and (2) the same AD hash was used on both sides of the gap, then anyone with privileged access on one side could access the other side using the same hash.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;* Hashes need to be upgraded as technology moves forward.&amp;#160; [https://www.nist.gov/news-events/news/2022/12/nist-retires-sha-1-cryptographic-algorithm NIST had deprecated SHA-1] so it should no longer be used for security solutions, like the hashing of secrets.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Attacks==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Attacks==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Tom</name></author>	</entry>

	<entry>
		<id>http://tcwiki.azurewebsites.net/index.php?title=Hashed_Password&amp;diff=15495&amp;oldid=prev</id>
		<title>Tom: Created page with &quot;==Full Title or Meme== A password should never be stored in plain text. or it can be copied out and used by an attacker.  ==Context== * Many providers store passwords locally...&quot;</title>
		<link rel="alternate" type="text/html" href="http://tcwiki.azurewebsites.net/index.php?title=Hashed_Password&amp;diff=15495&amp;oldid=prev"/>
				<updated>2022-08-12T22:00:19Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;==Full Title or Meme== A password should never be stored in plain text. or it can be copied out and used by an attacker.  ==Context== * Many providers store passwords locally...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==Full Title or Meme==&lt;br /&gt;
A password should never be stored in plain text. or it can be copied out and used by an attacker.&lt;br /&gt;
&lt;br /&gt;
==Context==&lt;br /&gt;
* Many providers store passwords locally by hashing the password used a secret number as a &amp;quot;salt&amp;quot; for the hashing algorithm.&lt;br /&gt;
* One example of a system using stored passwords is Microsoft AD.&lt;br /&gt;
* The concept is that the password is not stored in the prover, so it cannot be stolen from the provider.&lt;br /&gt;
&lt;br /&gt;
==Problem==&lt;br /&gt;
* If the password hash is taken from a provider, it can be used to sign-into that provider.&lt;br /&gt;
* In one well-known attack against air-gapped systems, many users had the same password in providers on both sides of the gap. So if (1) the password hash could be obtained in one side of the gap, and (2) the same AD hash was used on both sides of the gap, then anyone with privileged access on one side could access the other side using the same hash.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Attacks==&lt;br /&gt;
* [https://www.theregister.com/2022/08/08/slack_passwords/?utm_source=daily&amp;amp;utm_medium=newsletter&amp;amp;utm_content=article Slack leaked hashed passwords from its servers for years]&lt;br /&gt;
&lt;br /&gt;
==References==&lt;br /&gt;
&lt;br /&gt;
[[Category: Vulnerability]]&lt;/div&gt;</summary>
		<author><name>Tom</name></author>	</entry>

	</feed>