Md5 Memes

Posts tagged with Md5

A Website With Millions Of Users Was Generating Their "Secret" Password Reset Codes Like This For Two Decades

A Website With Millions Of Users Was Generating Their "Secret" Password Reset Codes Like This For Two Decades
Oh honey, buckle up because this is a MASTERCLASS in how to absolutely obliterate security for twenty years straight. Someone really looked at password reset codes and thought "you know what? Let's just use the current time and a random number under 10,000, hash it, and call it a day!" The predictability here is *chef's kiss* catastrophic. Since microtime() gives you the current timestamp and they're only adding a teeny tiny random number, an attacker could literally just... try a bunch of combinations around the current time. And then they're only taking 6 characters from the MD5 hash? That's like locking Fort Knox with a diary lock from Claire's. The fact that this code was PUBLICLY VISIBLE on GitHub for a DECADE while millions of users trusted their accounts to this digital wet paper bag of security is the kind of corporate negligence that should come with a free therapy session for every affected user. Someone's LinkedIn is about to get a lot quieter.

PHP's Accidental Hash Collision Feature

PHP's Accidental Hash Collision Feature
Behold, PHP's infamous type juggling strikes again! The meme shows how md5('240610708') == md5('QNKCDZO') evaluates to true despite being completely different strings. What's happening? Both MD5 hashes begin with '0e' followed by digits, which PHP helpfully interprets as scientific notation (0×10^something). And since 0 raised to any power equals 0, PHP thinks both hashes equal zero. It's basically comparing 0==0. This is why strict comparison ( === ) exists in PHP. Without it, you might accidentally authenticate someone with the wrong password! Security nightmare fuel for any developer who values their sanity.