National Institute of Standards and Technology
Package illustrating a test case

Test case 1947

Description

The test case shows a not so weak encryption practice. Here the password is stored in the cookie as a salted SHA-256 of the password. The salted passwords are a common technique to create a better hash, the salt should be inserted in a database... We use the cookie to communicate with the black box tool; it is a bad practice to store the password in the cookie.

Flaws

Test Suites

Have any comments on this test case? Please, send us an email.