Alex Rivera | Logout

Going from unsalted to salted MD5 passwords

Asked 2009-09-22T12:51:58.310
20

I have a LAMP (PHP) website which is becoming popular.

I played it safe by storing the user passwords as md5 hashes.

But I now see that's not secure; I should have salted the md5 hash - because it's currently possible to decode unsalted md5 hashes using rainbow tables.

What can I do?

I don't want to make everyone type a new password.

Edit
Report

1 Answer

5

Why not add a new column new_pwd to your user table, which stores the result of md5($originallyHashOfPwd . $salt). You can then precompute new_pwd and once that's done adjust your login checking to compare the result of md5(md5($entered_pwd) . $salt) to what's in new_pwd. Once you're done switching your login checking, delete the old column.

That should stop rainbow-table style attacks.

answered 2009-09-22T12:57:10.563

Your Answer