Password hashes #7
Labels
No labels
bug
come back to it later
duplicate
enhancement
help wanted
invalid
needs a review
needs to be tested
question
ready for testing
wontfix
work in progress
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: ungleich-public/dynamicweb#7
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Created by: DinarGataullin
Hi! This may be a security issue if the password hashes published in internet https://github.com/ungleich/dynamicweb/blob/master/latest_app_db_dump.db:
4 pbkdf2_sha256$15000$Y98E4iEKgL0S$bgf0Zo1vl3yshqYtACeP5paZpVbmgNc17w3YA/Zi5nc= 2016-03-20 23:07:50.015532+01 t samantha Samantha Meyer samantha.meyer@ungleich.ch t t 2016-03-17 09:37:30+01
Created by: telmich
Thanks a lot for the hint, Dinar!
Fortunately these have only been testing accounts, however we've still removed the dump that should never have been there!
By Mondi Ravi on 2016-04-03T18:10:59 (imported from GitLab project)