2026-09-22 16:34 UTC
Quiz time!
What is the vulnerability in the following construction?
`$hash = bcrypt($password . $pepper, $salt)`
salts are per-user 128-bit nonces, stored in DB.
pepper is a global 256-bit secret in base64, kept in an HSM.
passwords are user-chosen printable ASCII strings.
Application is a public web app.
Assume an attacker with read-only SQLi.
Replies (1)
-
@embers@chaos.social 2026-09-23 19:50
bcrypt truncates inputs after 72 bytes. An attacker can set their own password to a 71-byte string, extract the hash, and recover the first byte of the pepper. (they don't even need the SQLi, attempting to log in with `$71_byte_string . $pepper_guess` is just as good an oracle) They can then recover the entire pepper byte-by-byte by repeating this with shorter and shorter passwords. With the pepper leaked, they can use the SQLi to leak all hashes and begin cracking all passwords.