Elektrine lite

← Feed

@embers@chaos.social

2026-09-22 16:34 UTC

Quiz time! What is the vulnerability in the following construction? `$hash = bcrypt($password . $pepper, $salt)` salts are per-user 128-bit nonces, stored in DB. pepper is a global 256-bit secret in base64, kept in an HSM. passwords are user-chosen printable ASCII strings. Application is a public web app. Assume an attacker with read-only SQLi.

Replies (1)

  • @embers@chaos.social 2026-09-23 19:50

    bcrypt truncates inputs after 72 bytes. An attacker can set their own password to a 71-byte string, extract the hash, and recover the first byte of the pepper. (they don't even need the SQLi, attempting to log in with `$71_byte_string . $pepper_guess` is just as good an oracle) They can then recover the entire pepper byte-by-byte by repeating this with shorter and shorter passwords. With the pepper leaked, they can use the SQLi to leak all hashes and begin cracking all passwords.

    Open ##4834477