Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


How might this source be exploited? filter_list
Author
Message
RE: How might this source be exploited? #14
(03-19-2015, 04:02 AM)Brawler Wrote: It matters because it gives me questions about the application:
  1. He is using client side code for something that is typically done on the server side.... Is he concerned about the load on the server? Is he new?

But the check is done via index.php as specified in the form (If not, feel free to prove me otherwise). Why does the fact that he hashes the password before sending it to index.php make it any more vulnerable as opposed to if he didn't? Typically passwords are sent in plain text, hashed via php functions, and then compared to values in a database. So why does hashing the user given password on the clients end make it any less secure? The answer is no, it doesn't make a difference at all.

(03-19-2015, 04:02 AM)Brawler Wrote: They may not be relevant to you... But I'm a big fan paying attention to the small details.

I get the feeling that you think we are going to bruteforce logins through the application. This is not what we are saying.... What we would do in this situation is crack them offline.... At least that's what I would do.

Crack what offline? What the actual fuck do you plan to crack? You realize the "password" that is hashed is nothing more than user supplied input via the form, right? It's not the real password stored in the database, just the one you supply.

Code:
<input type="password" id="t3-password" name="p_field" value="" class="t3-password" tabindex="2" /> // this is where we get user supplied pass function doChallengeResponse(superchallenged) { // password = document.loginform.p_field.value; // user supplied pass is taken in this func and hashed <form action="index.php" method="post" name="loginform" onsubmit="doChallengeResponse(1);"><input type="hidden" name="challenge" value="0a632b550ce0fa1191167179c9df10e2" /><input type="hidden" name="login_status" value="login" /><input type="hidden" name="userident" value="" /><input type="hidden" name="redirect_url" value="backend.php" /><input type="hidden" name="loginRefresh" value="" /> // from takes hashed user supplied password and sends it as a post request to index.php backend

"0a632b550ce0fa1191167179c9df10e2" was the hash value generated from the password input form, which is THEN sent to the PHP backend to VALIDATE whether or not the password is valid or not. What are you not getting here? I could submit "Brawler is a fucking idiot" as a password and all it would do is send the md5 value of that to the php backend to be checked against a database value. What "offline cracking" do you plan on doing related to that? Are you gonna crack the hash of a value you submitted yourself?

(03-19-2015, 04:02 AM)Brawler Wrote: Also... Why the hell would you throttle your "backend"? CAPCHA.... Account lockout.... These are much better options without implementing some janky workarounds.

Please read the code in the OP/learn javascript before replying to me again. You obviously don't understand what the fuck is going on.

And "throttling user logins" is a synonym for what you call "Account lockout", moron.

Reply





Messages In This Thread
RE: How might this source be exploited? - by Dyme - 03-19-2015, 01:04 AM
RE: How might this source be exploited? - by Dyme - 03-19-2015, 01:21 AM
RE: How might this source be exploited? - by Dyme - 03-19-2015, 05:27 AM
RE: How might this source be exploited? - by Dyme - 03-19-2015, 01:06 PM