Results 1 to 4 of 4
Like Tree1Likes
  • 1 Post By gimbal2

Thread: Hashing password

  1. #1
    Programm3r is offline Member
    Join Date
    Sep 2014
    Posts
    5
    Rep Power
    0

    Default Hashing password

    Hi may I know the algorithm PBKDF2WithHmacSHA1 is the salt concat together with the hash here is what I am tried. I am not sure whether to store the salt as another column .

    String password = request.getParameter("password");

    char[] char = password.toCharArray();

    int salt = 16;

    int iteration = 800;

    int hashSize = 32;

    byte[] salt = SecureRandom.getInstance("SHA1PRNG").generateSeed( saltLen);

    PBEKeySpec spec = new PBEKeySpec(p, salt, iteration, hashSize);
    SecretKeyFactory secret = SecretKeyFactory.getInstance("PBKDF2WithHmacSHA256 ");
    byte[] hash = secret.generateSecret(spec).getEncoded();

  2. #2
    gimbal2 is offline Just a guy
    Join Date
    Jun 2013
    Location
    Netherlands
    Posts
    5,114
    Rep Power
    12

    Default Re: Hashing password

    This article may answer this question and all future questions you may have regarding password hashing and salting:

    https://crackstation.net/hashing-security.htm

    (Java example code included)
    "Syntactic sugar causes cancer of the semicolon." -- Alan Perlis

  3. #3
    Programm3r is offline Member
    Join Date
    Sep 2014
    Posts
    5
    Rep Power
    0

    Default Re: Hashing password

    Hi so far am i doing it correctly?

  4. #4
    gimbal2 is offline Just a guy
    Join Date
    Jun 2013
    Location
    Netherlands
    Posts
    5,114
    Rep Power
    12

    Default Re: Hashing password

    Read the article and find out.
    DarrylBurke likes this.
    "Syntactic sugar causes cancer of the semicolon." -- Alan Perlis

Similar Threads

  1. Hashing vs Array
    By suhaas_mohandos in forum New To Java
    Replies: 34
    Last Post: 05-16-2014, 10:56 PM
  2. Hashing
    By sravan_51 in forum New To Java
    Replies: 1
    Last Post: 12-28-2010, 05:47 AM
  3. how to check password for 3 times enterd wrong password
    By sk.mahaboobbhasha@gmail.c in forum New To Java
    Replies: 2
    Last Post: 11-14-2008, 08:53 PM
  4. how to check password for 3 times enterd wrong password
    By sk.mahaboobbhasha@gmail.c in forum Java Servlet
    Replies: 0
    Last Post: 11-14-2008, 02:22 PM
  5. How to check password of a jsp/html with the password of Database(mysql) #1
    By sk.mahaboobbhasha@gmail.c in forum Java Servlet
    Replies: 2
    Last Post: 11-14-2008, 02:11 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •