Hash Cracking is online - sort of

Problems with the hash cracking system? Suggestions?
  • Ads

Re: Hash Cracking is online - sort of

Postby Sc00bz » Sun Mar 29, 2009 11:18 pm

The MD5 of the following is insiderpro's answer b2d1969ce7ecf519a73d6b2f9c4f96e4
Code: Select all
íàòàøåíüêà

The correct MD5 of íàòàøåíüêà is 0b21692555efd2333df4cb69335609f3.

I used a packet sniffer to see what it was actually sending which was "%26%23237%3B%26%23224%3B%26%23242%3B%26%23224%3B%26%23248%3B%26%23229%3B%26%23237%3B%26%23252%3B%26%23234%3B%26%23224%3B" then just URL decode it to get "íàòàøåíüêà" and MD5 it which is b2d1969ce7ecf519a73d6b2f9c4f96e4.
Sc00bz
 
Posts: 93
Joined: Thu Jan 22, 2009 9:31 pm

Re: Hash Cracking is online - sort of

Postby Bitweasil » Mon Mar 30, 2009 12:05 am

Interesting! Thanks for looking into that. Looks like InsidePro is rather wrong. :)

Sc00bz - what's the hex input for the character string?
Bitweasil
Site Admin
 
Posts: 912
Joined: Tue Jan 20, 2009 4:26 pm

Re: Hash Cracking is online - sort of

Postby Sc00bz » Mon Mar 30, 2009 2:50 am

The hex of the input is ede0f2e0f8e5edfceae0
Sc00bz
 
Posts: 93
Joined: Thu Jan 22, 2009 9:31 pm

Re: Hash Cracking is online - sort of

Postby Bitweasil » Mon Mar 30, 2009 3:25 am

So entirely ASCII, just the >128 chars. Interesting.

The problem is that more and more, that's going to be represented as Unicode.
Bitweasil
Site Admin
 
Posts: 912
Joined: Tue Jan 20, 2009 4:26 pm

Re: Hash Cracking is online - sort of

Postby Reelix » Thu Apr 09, 2009 6:04 am

On the page: http://www.cryptohaze.com/addsolutions.php

If you go

098f6bcd4621d373cade4e832627b4f6:test

and click "Add solutions", it will say "1 solutions added." at the top of the page.

Every time you do this with the same hash / result, it will say "1 solution added." - This is very deceptive for submitters, since "Added" generally means "Added to the list". So, either the same entry is being added multiple times (Uniques beware), or it just validates, then adds, before checking if the hash already exists IN the database.

This will become a nightmare for when you're adding users, as the same (malicious) user could add the exact same hash thousands of times, and it would accept them all (Giving him 'Points' or whatever)

I think this needs to be fixed :)

On a side note, when are users being introduced?

It would be nice to go like:

http://www.cryptohaze.com/addhashes.php

Input 098f6bcd4621d373cade4e832627b4f6, click "Add hashes" and have:

098f6bcd4621d373cade4e832627b4f6:test (Solved By Reelix)

Also, the phrase "Hash 098f6bcd4621d373cade4e832627b4f6 is already in the database, password 'test' - skipping." is a bit superfluous - Shouldn't you just say:

098f6bcd4621d373cade4e832627b4f6:test

or

someRandomHash:Not Found

?

Oh well, enough of me going on - Enjoy your day :)
Reelix
 
Posts: 17
Joined: Thu Mar 26, 2009 10:51 pm

Re: Hash Cracking is online - sort of

Postby labbo » Thu Apr 09, 2009 8:11 am

I tried to add the hash
MD5 : 056E4D8F406CCA67F056BC48ECCD7683: ' 1.' 0x202020312E

on http://www.cryptohaze.com/addsolutions.php the response i get is
056E4D8F406CCA67F056BC48ECCD7683 is not the correct MD5 hash for ''

note it should be ' 1.'

edit* it should be tre spaces 1. between ' and 1 password should be 5 characters long.
labbo
 
Posts: 6
Joined: Mon Apr 06, 2009 8:01 pm

Re: Hash Cracking is online - sort of

Postby Bitweasil » Thu Apr 09, 2009 3:03 pm

I'm aware of some issues with the current solution setup - I'm working to change how that's handled and it will be updated in the new release.

On that, I've finished my pilot's license, so I'll have a bit more time for this now.
Bitweasil
Site Admin
 
Posts: 912
Joined: Tue Jan 20, 2009 4:26 pm

Previous

Return to Hash cracking

Who is online

Users browsing this forum: No registered users and 1 guest

cron