← Back to Advanced Java Course | Chapter 11: Advanced & Security | Lesson 12 of 19

Java में Hashing (MD5, SHA)

Hashing किसी भी data को एक छोटे fixed fingerprint में बदल देता है, ताकि आप जांच सकें कि यह बदला है या नहीं। इसे वापस नहीं पलटा जा सकता, जो इसे passwords के लिए उपयोगी बनाता है।
Syntax
java
MessageDigest digest = MessageDigest.getInstance("SHA-256");
byte[] hash = digest.digest(input.getBytes(StandardCharsets.UTF_8));

What is Hashing?

Hashing किसी भी input data को characters की एक fixed-length string में बदल देता है जो उस data का एक unique mathematical fingerprint की तरह काम करता है। यह जान-बूझकर एक-तरफ़ा process है -- किसी hash को उसके original input में वापस पलटने के लिए कोई algorithm नहीं है, जो बिल्कुल वही property है जो इसे data verify करने या passwords store करने के लिए उपयोगी बनाती है।

उदाहरण: What is Hashing?

java
import java.security.MessageDigest;
public class Main {
	public static void main(String[] args) throws Exception {
		MessageDigest digest = MessageDigest.getInstance("SHA-256");
		byte[] hash = digest.digest("hello".getBytes());
		System.out.println("Fixed length: " + hash.length + " bytes"); // one-way, no reverse algorithm exists
	}
}

MD5 Hashing

MD5 एक legacy, 128-bit hashing algorithm है। यह तेज़ है, लेकिन इसमें अच्छी तरह documented cryptographic vulnerabilities हैं (practical collision attacks सहित), इसलिए इसे कभी passwords या किसी भी ऐसी चीज़ को सुरक्षित करने के लिए उपयोग नहीं करना चाहिए जहां आज security असल में मायने रखती हो।

उदाहरण: MD5 Hashing

java
import java.security.MessageDigest;
public class Main {
	public static void main(String[] args) throws Exception {
		MessageDigest digest = MessageDigest.getInstance("MD5"); // fast but has known collision attacks
		byte[] hash = digest.digest("data".getBytes());
		System.out.println(hash.length + " bytes -- never use for passwords");
	}
}

SHA-256 Hashing

SHA-256, SHA-2 family का एक सुरक्षित, 256-bit hashing algorithm है। यह वर्तमान में data integrity verification और general cryptographic checks के लिए standard choice है, क्योंकि इसके लिखे जाने के समय इसके खिलाफ कोई practical attack ज्ञात नहीं है।

उदाहरण: SHA-256 Hashing

java
import java.security.MessageDigest;
public class Main {
	public static void main(String[] args) throws Exception {
		MessageDigest digest = MessageDigest.getInstance("SHA-256"); // current standard for integrity checks
		byte[] hash = digest.digest("data".getBytes());
		StringBuilder hex = new StringBuilder();
		for (byte b : hash) hex.append(String.format("%02x", b));
		System.out.println(hex);
	}
}

Password Salting

Salting किसी password को hash करने से पहले उसमें एक random value (salt) जोड़ता है, और resulting hash के साथ उस salt को store करता है। यह precomputed rainbow-table attacks से बचाता है, क्योंकि यह सुनिश्चित करता है कि एक जैसा password रखने वाले दो users अब भी पूरी तरह अलग stored hashes पाएं।

उदाहरण: Password Salting

java
import java.security.*;
public class Main {
	public static void main(String[] args) throws Exception {
		SecureRandom random = new SecureRandom();
		byte[] salt = new byte[16];
		random.nextBytes(salt); // random per user, stored alongside the hash
		MessageDigest digest = MessageDigest.getInstance("SHA-256");
		digest.update(salt);
		byte[] hash = digest.digest("password123".getBytes());
		System.out.println("Salted hash length: " + hash.length);
	}
}

Verifying Hashes

बाद में किसी password को verify करने के लिए, आप नए submit किए input के hash को उसी algorithm और उसी stored salt का उपयोग करके फिर से generate करते हैं, फिर resulting bytes को stored hash से compare करते हैं -- कभी भी original plaintext passwords को सीधे compare करके नहीं।

उदाहरण: Verifying Hashes

java
import java.security.*;
import java.util.Arrays;
public class Main {
	public static void main(String[] args) throws Exception {
		byte[] salt = "fixedSaltForDemo".getBytes();
		MessageDigest digest = MessageDigest.getInstance("SHA-256");
		digest.update(salt);
		byte[] storedHash = digest.digest("password123".getBytes());
		digest.reset();
		digest.update(salt);
		byte[] submittedHash = digest.digest("password123".getBytes()); // recomputed with the same salt
		System.out.println(Arrays.equals(storedHash, submittedHash));
	}
}
Related Topics
{# common_mistakes/chapter_summary/browser_support: on Hindi pages the view already swaps in the hi_ translation fields (or blanks these out if untranslated), so this renders correctly for both languages without a lang_code check here. #}
आम गलतियां
  1. passwords को plain MD5 या SHA-256 से store करना, जबकि ये बहुत तेज़ हैं और password storage को bcrypt या PBKDF2 जैसे धीमे algorithm की ज़रूरत है।
  2. बिना random salt के passwords को hash करना, जिससे बराबर passwords बराबर hashes देते हैं और rainbow tables काम करती हैं।
  3. बिना किसी charset के getBytes() call करना, जो platform default उपयोग करता है और अलग machines पर अलग hashes दे सकता है; StandardCharsets.UTF_8 का उपयोग करें।

Login to run this code

C/C++/Java/PHP execution requires a free account. Your code is saved — you'll land right back in the editor after logging in.