securing passwords
Ok, so my site was previously hacked, and I believe that the hacker probably got the md5 hashes of all the passwords, and is able to decrypt them.
Now assuming this, how do I move forward? I am taking every security measure possible while rebuilding my forum, but as long as the hacker already has those hashes, he could still compromise accounts once I am back up and running, right?
Is there anyway to re-hash those, or something, so that the data the hacker has would be useless?
|