webcalendar icon indicating copy to clipboard operation
webcalendar copied to clipboard

Using encryption instead of md5 hashes

Open bzsido opened this issue 6 years ago • 0 comments

I noticed, that this application is using the md5 hash function for password 'encryption'. This applies to the initial browser password (stored in webcalendar/includes/settings.php), and to the user passwords, stored in the webcal_user table of the database as well.

Md5 hashes are proven to be insecure, because they are vulnerable to collision attacks and can be cracked using rainbow tables (or by just simply googling a hash). It would be better to use the CRYPT mysql function or sha512 instead.

bzsido avatar Jul 31 '18 07:07 bzsido