Description
Storing passwords with fast hashes such as md5, sha1 or a general-purpose hash makes them vulnerable to offline guessing attacks.
Potential impact
If hashes are exposed, attackers may recover passwords quickly.
Remediation
Use password_hash and password_verify with PASSWORD_DEFAULT or supported PASSWORD_ARGON2ID.
Examples
Before
php
<?php
$hash = md5($password);
After
php
<?php
$hash = password_hash($password, PASSWORD_DEFAULT);
Explanation:
- Before: Uses a fast general-purpose hash instead of a dedicated password-hashing algorithm.
- After: Uses
password_hashwithPASSWORD_DEFAULT. Verify passwords withpassword_verify; supportedPASSWORD_ARGON2IDis another option.