?
Solved

vb.net Decode a SHA1 hash

Posted on 2009-04-07
4
Medium Priority
?
3,591 Views
Last Modified: 2012-05-06
I am using the function below to create an SHA1 hash of a username & password

now, given the username and the hash, how can i recover the password?

Private Function CreateHash(ByVal user As String, ByVal pass As String) As String
        Dim hashAlg As SHA1 = SHA1.Create
        Dim hashvalue() As Byte = hashAlg.ComputeHash(System.Text.Encoding.Default.GetBytes(UCase(user) & ":" & UCase(pass)))
        Dim hashstring As String = ""
        For Each b As Byte In hashvalue
            hashstring += b.ToString("x2")
        Next
        hashAlg = Nothing
        hashvalue = Nothing
        Return hashstring
    End Function

Open in new window

0
Comment
Question by:sgaggerj
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 8

Accepted Solution

by:
OBonio earned 2000 total points
ID: 24088432
A hash is not asymmetric which means it is one way.  Once hashed, you can't, in theory, 'unhash'.  You use hashes by comparing.  ie, input data is hashed and compared to previously computed hashes.
0
 
LVL 1

Author Comment

by:sgaggerj
ID: 24088690
that's what i figured....
0
 
LVL 8

Expert Comment

by:OBonio
ID: 24094892
If you're trying to unhash, you could look up rainbow tables....
0
 
LVL 1

Author Comment

by:sgaggerj
ID: 24097591
Took a look and it seems a lot more time consuming that I want to spend (cpu cycle wise) on doing what i wanted.
I found a workaround.

Essentially i had a login w/ a 'remember me' box that saved the login info - but when the app is updated the settings get overwritten and the user needs to type in the login/pass again.

i added a field to my db table with the user/pass hash and store that locally instead in a separate file that never gets written over. more secure and gets the job done.

thanks!
0

Featured Post

When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot has fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Since pre-biblical times, humans have sought ways to keep secrets, and share the secrets selectively.  This article explores the ways PHP can be used to hide and encrypt information.
Businesses who process credit card payments have to adhere to PCI Compliance standards. Here’s why that’s important.
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
Suggested Courses

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question