Java में Hashing (MD5, SHA)
MessageDigest digest = MessageDigest.getInstance("SHA-256");
byte[] hash = digest.digest(input.getBytes(StandardCharsets.UTF_8));
What is Hashing?
Hashing किसी भी input data को characters की एक fixed-length string में बदल देता है जो उस data का एक unique mathematical fingerprint की तरह काम करता है। यह जान-बूझकर एक-तरफ़ा process है -- किसी hash को उसके original input में वापस पलटने के लिए कोई algorithm नहीं है, जो बिल्कुल वही property है जो इसे data verify करने या passwords store करने के लिए उपयोगी बनाती है।
उदाहरण: What is Hashing?
import java.security.MessageDigest;
public class Main {
public static void main(String[] args) throws Exception {
MessageDigest digest = MessageDigest.getInstance("SHA-256");
byte[] hash = digest.digest("hello".getBytes());
System.out.println("Fixed length: " + hash.length + " bytes"); // one-way, no reverse algorithm exists
}
}
Login to try C/C++/Java/PHP code in the editor
MD5 Hashing
MD5 एक legacy, 128-bit hashing algorithm है। यह तेज़ है, लेकिन इसमें अच्छी तरह documented cryptographic vulnerabilities हैं (practical collision attacks सहित), इसलिए इसे कभी passwords या किसी भी ऐसी चीज़ को सुरक्षित करने के लिए उपयोग नहीं करना चाहिए जहां आज security असल में मायने रखती हो।
उदाहरण: MD5 Hashing
import java.security.MessageDigest;
public class Main {
public static void main(String[] args) throws Exception {
MessageDigest digest = MessageDigest.getInstance("MD5"); // fast but has known collision attacks
byte[] hash = digest.digest("data".getBytes());
System.out.println(hash.length + " bytes -- never use for passwords");
}
}
Login to try C/C++/Java/PHP code in the editor
SHA-256 Hashing
SHA-256, SHA-2 family का एक सुरक्षित, 256-bit hashing algorithm है। यह वर्तमान में data integrity verification और general cryptographic checks के लिए standard choice है, क्योंकि इसके लिखे जाने के समय इसके खिलाफ कोई practical attack ज्ञात नहीं है।
उदाहरण: SHA-256 Hashing
import java.security.MessageDigest;
public class Main {
public static void main(String[] args) throws Exception {
MessageDigest digest = MessageDigest.getInstance("SHA-256"); // current standard for integrity checks
byte[] hash = digest.digest("data".getBytes());
StringBuilder hex = new StringBuilder();
for (byte b : hash) hex.append(String.format("%02x", b));
System.out.println(hex);
}
}
Login to try C/C++/Java/PHP code in the editor
Password Salting
Salting किसी password को hash करने से पहले उसमें एक random value (salt) जोड़ता है, और resulting hash के साथ उस salt को store करता है। यह precomputed rainbow-table attacks से बचाता है, क्योंकि यह सुनिश्चित करता है कि एक जैसा password रखने वाले दो users अब भी पूरी तरह अलग stored hashes पाएं।
उदाहरण: Password Salting
import java.security.*;
public class Main {
public static void main(String[] args) throws Exception {
SecureRandom random = new SecureRandom();
byte[] salt = new byte[16];
random.nextBytes(salt); // random per user, stored alongside the hash
MessageDigest digest = MessageDigest.getInstance("SHA-256");
digest.update(salt);
byte[] hash = digest.digest("password123".getBytes());
System.out.println("Salted hash length: " + hash.length);
}
}
Login to try C/C++/Java/PHP code in the editor
Verifying Hashes
बाद में किसी password को verify करने के लिए, आप नए submit किए input के hash को उसी algorithm और उसी stored salt का उपयोग करके फिर से generate करते हैं, फिर resulting bytes को stored hash से compare करते हैं -- कभी भी original plaintext passwords को सीधे compare करके नहीं।
उदाहरण: Verifying Hashes
import java.security.*;
import java.util.Arrays;
public class Main {
public static void main(String[] args) throws Exception {
byte[] salt = "fixedSaltForDemo".getBytes();
MessageDigest digest = MessageDigest.getInstance("SHA-256");
digest.update(salt);
byte[] storedHash = digest.digest("password123".getBytes());
digest.reset();
digest.update(salt);
byte[] submittedHash = digest.digest("password123".getBytes()); // recomputed with the same salt
System.out.println(Arrays.equals(storedHash, submittedHash));
}
}
Login to try C/C++/Java/PHP code in the editor
- passwords को plain
MD5याSHA-256से store करना, जबकि ये बहुत तेज़ हैं और password storage को bcrypt या PBKDF2 जैसे धीमे algorithm की ज़रूरत है। - बिना random salt के passwords को hash करना, जिससे बराबर passwords बराबर hashes देते हैं और rainbow tables काम करती हैं।
- बिना किसी charset के
getBytes()call करना, जो platform default उपयोग करता है और अलग machines पर अलग hashes दे सकता है;StandardCharsets.UTF_8का उपयोग करें।
Chapter Quiz — Complete all 19 topics to unlock
0/19 topics done
Complete these topics first:
- Java Reflection API
- Java Annotations Advanced
- Java Garbage Collection
- Java Memory Management
- Java Performance Optimization
- Java Advanced Interview Questions
- Java CompletableFuture
- Java Atomic Classes
- Java Locks & Semaphores
- Java Concurrent Collections
- Java Cryptography Basics
- Java Hashing (MD5, SHA)
- Java SSL & HTTPS
- Java Logging (Log4j/SLF4J)
- Java Serialization Advanced
- Java Interview Questions Advanced
- Java Connection Pooling
- Java Test Driven Development
- Java Integration Testing