CWE-836: Use of Password Hash Instead of Password for Authentication

CWE-836 là gì?

MITRE CWE

The product records password hashes in a data store, receives a hash of a password from a client, and compares the supplied hash to the hash obtained from the data store.

Xác minh để phân tích mục CWE này

Bước xác minh ngắn giúp bảo vệ nguồn dữ liệu chính thức và hạn chế việc gọi AI tự động.

Mô tả chi tiết

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.

Đặc điểm

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.

Tác động thường gặp

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.

Biện pháp giảm thiểu

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.

Phương pháp phát hiện

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.

Lỗ hổng điển hình

CyStack đang phân tích mục CWE này. Trang sẽ tự động cập nhật khi bản phân tích song ngữ hoàn tất.
Dữ liệu MITRE CWE chính thứcMITRE CWE

Các trường dữ liệu và bằng chứng gốc từ hồ sơ MITRE CWE.

Nội dung gốc của MITRE được hiển thị bằng tiếng Anh khi nguồn không có bản địa hóa.

Định nghĩa MITRE gốc (tiếng Anh)

MITRE CWE

The product records password hashes in a data store, receives a hash of a password from a client, and compares the supplied hash to the hash obtained from the data store.

Some authentication mechanisms rely on the client to generate the hash for a password, possibly to reduce load on the server or avoid sending the password across the network. However, when the client is used to generate the hash, an attacker can bypass the authentication by obtaining a copy of the hash, e.g. by using SQL injection to compromise a database of authentication credentials, or by exploiting an information exposure. The attacker could then use a modified client to replay the stolen hash without having knowledge of the original password.

As a result, the server-side comparison against a client-side hash does not provide any more security than the use of passwords without hashing.

Giai đoạn hình thành

  • Hiện thực hóa: REALIZATION: This weakness is caused during implementation of an architectural security tactic.

Tác động thường gặp

  • Kiểm soát truy cập

    Vượt qua cơ chế bảo vệ, Chiếm đặc quyền hoặc mạo danh

    An attacker could bypass the authentication routine without knowing the original password.

Lỗ hổng điển hình

Các ví dụ này chỉ minh họa cho mục CWE, không phải danh sách đầy đủ mọi lỗ hổng liên quan.

  • CVE-2009-1283Product performs authentication with user-supplied password hashes that can be obtained from a separate SQL injection vulnerability (CVE-2009-1282).
  • CVE-2005-3435Product allows attackers to bypass authentication by obtaining the password hash for another user and specifying the hash in the pwd argument.

Nguồn và tài liệu tham khảo

CWE™ Program, operated by The MITRE Corporation. Copyright © 2006–2026, The MITRE Corporation. The MITRE Corporation hereby grants you a non-exclusive, royalty-free license to use CWE for research, development, and commercial purposes. CWE Terms of Use.

Tìm hiểu thêm

Kiểm tra chuyên sâu cùng giải pháp quản lý rủi ro Web toàn diện

Giải pháp CyStack VulnScan liên tục phát hiện tài sản, xác minh lỗ hổng và giúp đội ngũ bảo mật ưu tiên khắc phục cho toàn bộ doanh nghiệp.

Khám phá CyStack VulnScan
CyStack VulnScan dashboard