logo

Database

Java Pbkdf2 Insufficient Iteration Count

Description

This detector identifies Java code that derives keys with PBKDF2 using an iteration count below the OWASP minimum for the chosen hash function. A low iteration count makes derived keys and password hashes cheap to brute force, since modern hardware can compute them very quickly.

Weakness:

052 - Insecure encryption algorithm

Category: Information Collection

Detection Strategy

    • The code must import the javax.crypto package

    • The detector examines generateSecret calls and resolves the SecretKeyFactory algorithm (PBKDF2WithHmacSHA1, PBKDF2WithHmacSHA256 or PBKDF2WithHmacSHA512), including algorithm names held in constants or selected between alternatives

    • It resolves the PBEKeySpec passed to generateSecret, whether it is created inline or through a variable, and examines its iteration count, the third constructor argument

    • A vulnerability is reported when the iteration count is a literal, or a value that resolves to one, below the minimum for the algorithm: 1,400,000 for SHA-1, 600,000 for SHA-256 and 220,000 for SHA-512

    • Iteration counts received as method parameters are not reported

Vulnerable code example

import java.security.SecureRandom;
import java.security.spec.KeySpec;
import javax.crypto.SecretKeyFactory;
import javax.crypto.spec.PBEKeySpec;

class WeakIterationCount {
    static byte[] deriveKey(String secret) throws Exception {
        byte[] salt = new byte[16];...

✅ Secure code example

import java.security.SecureRandom;
import java.security.spec.KeySpec;
import javax.crypto.SecretKeyFactory;
import javax.crypto.spec.PBEKeySpec;

class StrongIterationCount {
    static byte[] deriveKey(String secret) throws Exception {
        byte[] salt = new byte[16];...