04-05-2005, 04:14 PM
|
#3 |
| Too much time... FlashFXP Beta Tester ioFTPD Scripter
Join Date: May 2003
Posts: 1,364
| router: The hash collisions found in MD5 and SHA-1 (and others) only affect hashes, not HMAC based handshakes (supported by SSL v3 and TLS v1).
However, the SHA-1 password hashes stored in ioFTPD's user-files would be affected. But this is a very low-risk threat; since the attacker would need physical access to ioFTPD's user-files to leverage hash collision during brute forcing.
|
| |