Java Pbkdf2 Insufficient Iteration Count
Description
This detector identifies Java code that derives keys with PBKDF2 using an iteration count below the OWASP minimum for the chosen hash function. A low iteration count makes derived keys and password hashes cheap to brute force, since modern hardware can compute them very quickly.
Detection Strategy
• The code must import the javax.crypto package
• The detector examines generateSecret calls and resolves the SecretKeyFactory algorithm (PBKDF2WithHmacSHA1, PBKDF2WithHmacSHA256 or PBKDF2WithHmacSHA512), including algorithm names held in constants or selected between alternatives
• It resolves the PBEKeySpec passed to generateSecret, whether it is created inline or through a variable, and examines its iteration count, the third constructor argument
• A vulnerability is reported when the iteration count is a literal, or a value that resolves to one, below the minimum for the algorithm: 1,400,000 for SHA-1, 600,000 for SHA-256 and 220,000 for SHA-512
• Iteration counts received as method parameters are not reported
Vulnerable code example
import java.security.SecureRandom;
import java.security.spec.KeySpec;
import javax.crypto.SecretKeyFactory;
import javax.crypto.spec.PBEKeySpec;
class WeakIterationCount {
static byte[] deriveKey(String secret) throws Exception {
byte[] salt = new byte[16];...✅ Secure code example
import java.security.SecureRandom;
import java.security.spec.KeySpec;
import javax.crypto.SecretKeyFactory;
import javax.crypto.spec.PBEKeySpec;
class StrongIterationCount {
static byte[] deriveKey(String secret) throws Exception {
byte[] salt = new byte[16];...Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' pentesting team, fill out this contact form.