Weak password hashing

Weak password hashing

Description

Storing passwords with fast hashes such as md5, sha1 or a general-purpose hash makes them vulnerable to offline guessing attacks.

Potential impact

If hashes are exposed, attackers may recover passwords quickly.

Remediation

Use password_hash and password_verify with PASSWORD_DEFAULT or supported PASSWORD_ARGON2ID.

Examples

Before

php
<?php
$hash = md5($password);

After

php
<?php
$hash = password_hash($password, PASSWORD_DEFAULT);

Explanation:

  • Before: Uses a fast general-purpose hash instead of a dedicated password-hashing algorithm.
  • After: Uses password_hash with PASSWORD_DEFAULT. Verify passwords with password_verify; supported PASSWORD_ARGON2ID is another option.

References