ungleich / dynamicweb

8 stars 22 forks source link

Password hashes #12

Closed DinarGataullin closed 8 years ago

DinarGataullin commented 8 years ago

Hi! This may be a security issue if the password hashes published in internet https://github.com/ungleich/dynamicweb/blob/master/latest_app_db_dump.db: 4 pbkdf2_sha256$15000$Y98E4iEKgL0S$bgf0Zo1vl3yshqYtACeP5paZpVbmgNc17w3YA/Zi5nc= 2016-03-20 23:07:50.015532+01 t samantha Samantha Meyer samantha.meyer@ungleich.ch t t 2016-03-17 09:37:30+01

telmich commented 8 years ago

Thanks a lot for the hint, Dinar!

Fortunately these have only been testing accounts, however we've still removed the dump that should never have been there!