Wireshark捕获MySQL流量时密码哈希异常问题咨询
mysql_native_password Authentication (Why Captured Password Hashes Change Every Time) Hey Eric, let's break down what's happening here—this is actually how MySQL's mysql_native_password authentication works by design, not an issue with your Wireshark capture or setup.
Why the captured "password" changes every login
MySQL uses a challenge-response authentication flow for mysql_native_password, which explains the unique hash per login:
- When you start a login attempt, the MySQL server sends a random 20-byte "challenge string" (salt) to your client.
- Your MySQL client takes this salt, combines it with the double-SHA1 hash of your plaintext password (this is what’s stored in your database), then runs SHA1 on the combined value.
- This final computed value is what you’re seeing in Wireshark as the "Password" field. Since the salt is random for every login, the result will always be different.
Why it doesn’t match the hash in your database
The hash stored in your MySQL database is SHA1(SHA1(plaintext_password))—let’s call this your "stored hash". The value sent by the client is a completely different computation:
Client-sent value = SHA1( salt + stored_hash )
That’s why the two values never match: they’re derived from different inputs (one is just the double-hashed password, the other is the salt plus that double-hashed password, re-hashed).
How the server verifies the login
The server doesn’t need your plaintext password to approve the login:
- It pulls your stored hash from the
mysql.usertable (note: in newer MySQL versions, this column is namedauthentication_string). - It takes the same salt it sent to your client, combines it with the stored hash, and runs SHA1 on the combination.
- It compares this computed value to the one sent by the client. If they match, the login is approved.
Quick way to test this logic
If you want to confirm this behavior manually:
- Grab the salt from the server’s initial handshake packet (Wireshark labels this as the "Auth Plugin Data" field).
- Retrieve your stored hash using
SELECT authentication_string FROM mysql.user WHERE user='root';. - Concatenate the salt and stored hash, then run SHA1 on the combined bytes. The result will exactly match the "Password" value in your Wireshark capture.
This mechanism is intentionally secure even over unencrypted connections: it prevents attackers from capturing a reusable hash (since each salt is unique) and avoids sending either the plaintext password or the stored hash directly.
内容的提问来源于stack exchange,提问作者Eric P

