Insecure encryption algorithm - MD5
Description
The web application uses insecure algorithms such as MD5 to hash passwords.
Impact
Crack captured credential easily.
Recommendation
Use secure hashing algorithms to store passwords like PBKDF2.
Threat
Authenticated attacker from the Internet with compromised DB hashes.
Expected Remediation Time
⏱️ 30 minutes.
Requirements
148 - Set minimum size of asymmetric encryption150 - Set minimum size for hash functionsRules
Ssl Tls Certificate Weak Signature Md5Swift Weak Hash Md5Typescript Sensitive Information Weak Md5Dart Weak Hash Md5Javascript Sensitive Information Weak Md5Typescript Insecure Md5 EncryptionRuby Sensitive Information Weak Md5Javascript Cryptojs Passphrase ModeJavascript Insecure Md5 EncryptionTypescript Cryptojs Passphrase Mode