sunsetting
Ostatnio znalazłem stronkę podatną na Remote File Inclusion postawioną na OsCommerce. Pobrałem zrzut bazy do siebie. I tu pojawia się problem. Oto kawałek bazy:
Cytat: drop table if exists admin;
create table admin (
admin_id int(11) not null auto_increment,
admin_groups_id int(11) ,
admin_firstname varchar(32) not null ,
admin_lastname varchar(32) ,
admin_email_address varchar(96) not null ,
admin_password varchar(40) not null ,
admin_created datetime ,
admin_modified datetime default '0000-00-00 00:00:00' not null ,
admin_logdate datetime ,
admin_lognum int(11) default '0' not null ,
PRIMARY KEY (admin_id),
UNIQUE admin_email_address (admin_email_address)
);
insert into admin (admin_id, admin_groups_id, admin_firstname, admin_lastname, admin_email_address, admin_password, admin_created, admin_modified, admin_logdate, admin_lognum) values ('1', '1', 'XXX', 'XXX', 'XXX', '73fcdf581f0c40e36245b631e2f11132:11', '2003-11-27 22:17:07', '2008-01-10 23:02:54', '2008-04-12 10:03:15', '82');
insert into admin (admin_id, admin_groups_id, admin_firstname, admin_lastname, admin_email_address, admin_password, admin_created, admin_modified, admin_logdate, admin_lognum) values ('2', '1', 'XXX', 'XXX', 'XXX', '17b581b79960730f3f310a8da0b8432f:6d', '2007-11-22 11:39:57', '2007-11-22 11:41:35', '2007-11-22 11:41:04', '1');
insert into admin (admin_id, admin_groups_id, admin_firstname, admin_lastname, admin_email_address, admin_password, admin_created, admin_modified, admin_logdate, admin_lognum) values ('3', '1', 'XXX', 'XXX', 'XXX', '48fdef6f98f93a71c42b47a223db826a:34', '2007-11-30 11:53:40', '2007-11-30 11:55:32', '2007-11-30 11:56:34', '2');
W haśle widzę 32 znaki przed ':' i 2 po nim. Czy to oznacza zlepek md5 + salt??? Chyba nie sądze...
pobierz OsCommerce i zobacz jak jest rozwiązana tam rejestracja całkiem możliwe, że to salt poza tym niekoniecznie musi to być md5
look
Może się przydadzą takie 2 linki:
http://hash.insidepro.com/
http://forum.insidepro.com/