this post was submitted on 26 May 2025
562 points (96.2% liked)

Cybersecurity - Memes

2683 readers
1 users here now

Only the hottest memes in Cybersecurity

founded 2 years ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 2 points 1 week ago
  1. Aquire password database (it's properly hashed and salted)
  2. Create an account and access the password reset form
  3. Dig into the front-end code to find whatever is doing the hash calculations
  4. Brute-force a list of common passwords and look for matches

It would still take significant time, but it's still a vulnerability, especially as technology evolves. You're right that best practices are different for a reset form, but there are some things that are common (like don't do hashes in the front end).