[Full-disclosure] Hardcoded Keys
Samuel Beckett
beckett.samuel at gmail.com
Wed Sep 3 10:31:25 BST 2008
What would be the the worst case if you implement the following scenario for
a credit card transaction:
- Store the private keys as disk files and place them in an area on a server
that is readable from a DLL that contains the decryption algorithm
-Hardcode one password into a DLL and the other password will be supplied by
the service that requests the decryption. This password is then SHA1 hashed
with a passphrase -- the result is used to decrypt the private key.
After the successful credit card transaction, certain credit card details
are then encrypted and stored within the database.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20080903/83b96aec/attachment.html
Full-Disclosure is hosted and sponsored by Secunia.