Description
Storing passwords with a fast hash such as SHA-256, or configuring a password hasher with too few iterations, lets an attacker make rapid offline guesses against stolen hashes.
Potential impact
- A database leak can lead to password recovery, account takeover and privilege escalation.
Remediation
Use ASP.NET Core PasswordHasher, bcrypt, Argon2, scrypt, or PBKDF2 with sufficient work and per-password salts.
Examples
Before
csharp
return SHA256.HashData(Encoding.UTF8.GetBytes(password));
After
csharp
var hasher = new PasswordHasher<User>();
return hasher.HashPassword(user, password);
Explanation:
- Before: Fast hashes and low password-hashing work factors let attackers test guesses efficiently offline.
- After: Use ASP.NET Core PasswordHasher, bcrypt, Argon2, scrypt or PBKDF2 with a suitable work factor and a separate salt for each password.