You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Wireshark捕获MySQL流量时密码哈希异常问题咨询

Understanding MySQL's mysql_native_password Authentication (Why Captured Password Hashes Change Every Time)

Hey Eric, let's break down what's happening here—this is actually how MySQL's mysql_native_password authentication works by design, not an issue with your Wireshark capture or setup.

Why the captured "password" changes every login

MySQL uses a challenge-response authentication flow for mysql_native_password, which explains the unique hash per login:

  • When you start a login attempt, the MySQL server sends a random 20-byte "challenge string" (salt) to your client.
  • Your MySQL client takes this salt, combines it with the double-SHA1 hash of your plaintext password (this is what’s stored in your database), then runs SHA1 on the combined value.
  • This final computed value is what you’re seeing in Wireshark as the "Password" field. Since the salt is random for every login, the result will always be different.

Why it doesn’t match the hash in your database

The hash stored in your MySQL database is SHA1(SHA1(plaintext_password))—let’s call this your "stored hash". The value sent by the client is a completely different computation:

Client-sent value = SHA1( salt + stored_hash )

That’s why the two values never match: they’re derived from different inputs (one is just the double-hashed password, the other is the salt plus that double-hashed password, re-hashed).

How the server verifies the login

The server doesn’t need your plaintext password to approve the login:

  1. It pulls your stored hash from the mysql.user table (note: in newer MySQL versions, this column is named authentication_string).
  2. It takes the same salt it sent to your client, combines it with the stored hash, and runs SHA1 on the combination.
  3. It compares this computed value to the one sent by the client. If they match, the login is approved.

Quick way to test this logic

If you want to confirm this behavior manually:

  1. Grab the salt from the server’s initial handshake packet (Wireshark labels this as the "Auth Plugin Data" field).
  2. Retrieve your stored hash using SELECT authentication_string FROM mysql.user WHERE user='root';.
  3. Concatenate the salt and stored hash, then run SHA1 on the combined bytes. The result will exactly match the "Password" value in your Wireshark capture.

This mechanism is intentionally secure even over unencrypted connections: it prevents attackers from capturing a reusable hash (since each salt is unique) and avoids sending either the plaintext password or the stored hash directly.

内容的提问来源于stack exchange,提问作者Eric P

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:31:42