﻿<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>博客园-小彬的Blog-最新评论</title><link>http://www.cnblogs.com/binblog/CommentsRSS.aspx</link><description /><language>zh-cn</language><pubDate>Tue, 03 Jan 2012 04:42:45 GMT</pubDate><lastBuildDate>Tue, 03 Jan 2012 04:42:45 GMT</lastBuildDate><generator>cnblogs</generator><item><title>Re:QQ的密码是明文的吗</title><link>http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285605</link><dc:creator>hanqg</dc:creator><author>hanqg</author><pubDate>Tue, 03 Jan 2012 09:08:57 GMT</pubDate><guid>http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285605</guid><description><![CDATA[看到标题吓一跳，还好理越辩越明<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/binblog/" target="_blank">hanqg</a> 2012-01-03 17:08 <a href="http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285605#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Re:QQ的密码是明文的吗</title><link>http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285602</link><dc:creator>不能飚车</dc:creator><author>不能飚车</author><pubDate>Tue, 03 Jan 2012 09:07:34 GMT</pubDate><guid>http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285602</guid><description><![CDATA[哈哈～～～看来写博也不能理清思路啊～～楼上的同学们都说的很多了<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/binblog/" target="_blank">不能飚车</a> 2012-01-03 17:07 <a href="http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285602#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Re:QQ的密码是明文的吗</title><link>http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285556</link><dc:creator>右丞相</dc:creator><author>右丞相</author><pubDate>Tue, 03 Jan 2012 07:27:52 GMT</pubDate><guid>http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285556</guid><description><![CDATA[验证码不需要进行MD5

网络传输密码时采用密钥加密，对于网站服务器，这个加密过程是可逆的；而对于其他人，由于不知道密钥，是无法进行解密的。

而验证码的存在，正是为了防止被暴力破解，这个验证码，甚至可以在客户端生成，只要验证码不正确，程序可以不向服务器提交请求；就算验证码是在服务端生成，如果不正确，那么服务器可以不去验证密码，直接返回一个登陆失败。

验证码明文传输又能如何？每次登陆都不一样，一个登陆过程结束以后，这条验证码也就没有用了，就按普通的四个英文字母组成的验证码，也有多达45万（26的四次方）个不同的值，对付暴力破解绰绰有余。<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/binblog/" target="_blank">右丞相</a> 2012-01-03 15:27 <a href="http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285556#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Re:QQ的密码是明文的吗</title><link>http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285550</link><dc:creator>Seariver Coding</dc:creator><author>Seariver Coding</author><pubDate>Tue, 03 Jan 2012 07:19:49 GMT</pubDate><guid>http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285550</guid><description><![CDATA[太不靠谱了，怎么得出的这个结果？照这样推理，只要使用验证码的网站，都存储的是明文！这种案例我们老师在密码学的课堂上就给我们分析过，随机验证码作为会话密钥而已，看来是楼主把自己绕进去了！<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/binblog/" target="_blank">Seariver Coding</a> 2012-01-03 15:19 <a href="http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285550#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Re:QQ的密码是明文的吗</title><link>http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285508</link><dc:creator>补丁</dc:creator><author>补丁</author><pubDate>Tue, 03 Jan 2012 05:49:37 GMT</pubDate><guid>http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285508</guid><description><![CDATA[分析的些啥啊,不靠谱<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/binblog/" target="_blank">补丁</a> 2012-01-03 13:49 <a href="http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285508#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Re:QQ的密码是明文的吗</title><link>http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285505</link><dc:creator>翅膀的初衷</dc:creator><author>翅膀的初衷</author><pubDate>Tue, 03 Jan 2012 05:47:05 GMT</pubDate><guid>http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285505</guid><description><![CDATA[QQ密码是三次MD5!<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/binblog/" target="_blank">翅膀的初衷</a> 2012-01-03 13:47 <a href="http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285505#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Re:QQ的密码是明文的吗</title><link>http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285503</link><dc:creator>Genius Zhang</dc:creator><author>Genius Zhang</author><pubDate>Tue, 03 Jan 2012 05:44:12 GMT</pubDate><guid>http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285503</guid><description><![CDATA[QQ应该是存三次MD5的结果，下次比对的时候，直接拿结果和验证码进行再次MD5，再进行对比就可以了<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/binblog/" target="_blank">Genius Zhang</a> 2012-01-03 13:44 <a href="http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285503#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Re:QQ的密码是明文的吗</title><link>http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285501</link><dc:creator>Genius Zhang</dc:creator><author>Genius Zhang</author><pubDate>Tue, 03 Jan 2012 05:43:18 GMT</pubDate><guid>http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285501</guid><description><![CDATA[[quote]寒霭：为什么验证码也要md5?[/quote]
出于安全考虑吧，因为每次验证码不同，这样传输回服务器的时候，每次传回来的MD5值也都不同，虽然密码是一样的<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/binblog/" target="_blank">Genius Zhang</a> 2012-01-03 13:43 <a href="http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285501#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Re:QQ的密码是明文的吗</title><link>http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285499</link><dc:creator>寒霭</dc:creator><author>寒霭</author><pubDate>Tue, 03 Jan 2012 05:22:53 GMT</pubDate><guid>http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285499</guid><description><![CDATA[为什么验证码也要md5?<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/binblog/" target="_blank">寒霭</a> 2012-01-03 13:22 <a href="http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285499#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item><item><title>Re:QQ的密码是明文的吗</title><link>http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285493</link><dc:creator>xinyu.zhang</dc:creator><author>xinyu.zhang</author><pubDate>Tue, 03 Jan 2012 05:02:01 GMT</pubDate><guid>http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285493</guid><description><![CDATA[楼主的思路是 用户名+密码+验证码 （md5） = 哈希值 -&gt; 服务器端验证，由于验证码每次都不相同，故服务器端无法储存静态哈希值进行验证。
可不可以这样：
服务器端储存 用户名+密码（md5） 的哈希值 （value1）
客户端输入： 用户名、密码、验证码
用户名+验证码（md5）= 哈希值 + 验证码 （md5） = 哈希值 -&gt; 服务器
服务器端：(value1) + 验证码（md5） = 哈希值
用这两个值比较，一样则成功<br><br><div align=right><a style="text-decoration:none;" href="http://www.cnblogs.com/binblog/" target="_blank">xinyu.zhang</a> 2012-01-03 13:02 <a href="http://www.cnblogs.com/binblog/archive/2012/01/03/2310912.html#2285493#Feedback" target="_blank" style="text-decoration:none;">发表评论</a></div>]]></description></item></channel></rss>
