h = HASH.new()
HASH.update(password)
HASH.update(salt)
for x in xrange(X):
HASH.update(HASH.digest())
return HASH.digest()
this approach "strengths" the hash by forcing you to calculate it over and over again. You should set X to be the number of rounds you want to conduct. Ie. how slow you want you server to respond to an individual request. It is always a trade-off between server slowness for individual requests and "security" of the hash function. The goal is to make dictionary attacks take longer than is feasible for you attackers to conduct.[Note: you should absolutely have a different salt for each password with this approach.]