Hacker News new | past | comments | ask | show | jobs | submit login

A hardcoded second salt is called a pepper, and some programs use it. Unfortunately, with a popular and outdated PHP app like VBulletin, it won't be too difficult for an attacker to obtain both the DB dump and whatever configuration file that contains the pepper. All those PHP files just sit inside the document root, and everyone knows exactly where they are.



Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: