Securing password hashes from SQL injection attacks using Image Steganography
Thomas Ronil George · NORMA · 2018
SQL injection attacks can display hashed passwords on screen and it becomes accessible to unauthorized users. With access to the hashed password, it is not very difficult to identify the algorithm that was used to hash the password and decode it. This paper is intended for back-end or full stack developers who use SQL database systems to store hashed passwords in databases for user registration and login systems. The proposed method is to obfuscate password hashes in images using steganography, and to place them in a secure location rather than a database. These steganographic images will be used again for the login process. The key motivation for this paper is that a hash, when visible is quite intriguing and can help in learning patterns and algorithms. This paper demonstrates the successful implementation of a user registration and login system using image steganography for password storage.