Zero Identity
Username: Password:
[Forgot Password?] [Not Registered?]

ZI Store Updates

Zi Store

Online Users

Registered Users: 1426
Latest Registration: gohan
Online Users: 11
(0 Members, 11 Guests)

Poll

What should be done with ZI from here on out?
Get the staff to come back and work on it. (19%) [13 Votes]
Shutdown the site. (2%) [2 Votes]
Leave it to rot. (1%) [1 Votes]
Get new staff to work on it. (76%) [52 Votes]

[Poll Archive]


Icon Zero Identity Forums - General - Cryptology - crack md5 with salt


Are you bored? Check out the unaswered threads!

Tux
Veteran Member
the killer penguin

Avatar
Professional Analyst

Joined: 03.04.2008
Last Seen: 10 year(s) ago
Experience: 579.08
Points: 585
#1 crack md5 with salt on October 11 2008 23:50
hey guys,

i'm not very good at hash cracking, and i have some md5's with 32 char salts on them. any advice on the easiest way to crack them? i have an excellent wordlist and jtc, i'm just not sure how to use jtr with salt.

thanks an oodle,

tux.

<person i was helping> says:
SELECT ' UNION ALL FROM users?
bigggnick@gmail.com says:
lol
person says:
SELECT 'UNION ALL' FROM users?

LEARN SQL BEFORE ATTEMPTING TO INJECT IT!!!!!!
MarianG
Member
Devil in Nirvana.

Avatar
Professional Analyst

Joined: 25.08.2008
Last Seen: 03 month(s) ago
Experience: 177.1
Points: 1470
#2 RE: crack md5 with salt on October 12 2008 01:28
Try with Cain & Abel. :)

Code Highlighting :: Select Code
UPDATE world SET genius="1" WHERE nick="MarianG";

7 --- 13 --- 23 --- 666 --- 90213.
Good Luck - Bad Luck - Destiny - Devil - MarianG
Image
rohansingh47
Member


Avatar
Professional Analyst

Joined: 17.07.2008
Last Seen: 10 year(s) ago
Experience: 1005.63
Points: 565
#3 RE: crack md5 with salt on October 12 2008 01:50
try this http://www.milw0rm.com/cracker/insert.php

Image
I would love to change the world, but they won't give me the source code

Tux
Veteran Member
the killer penguin

Avatar
Professional Analyst

Joined: 03.04.2008
Last Seen: 10 year(s) ago
Experience: 579.08
Points: 585
#4 RE: crack md5 with salt on October 12 2008 09:46
neither of those will work because of the salt. thanks for the replys, tho.

<person i was helping> says:
SELECT ' UNION ALL FROM users?
bigggnick@gmail.com says:
lol
person says:
SELECT 'UNION ALL' FROM users?

LEARN SQL BEFORE ATTEMPTING TO INJECT IT!!!!!!
scankyfrank
Veteran Member
King of the Jews

Avatar
Professional Analyst

Joined: 03.04.2008
Last Seen: 10 year(s) ago
Experience: 865.28
Points: 220
#5 RE: crack md5 with salt on October 12 2008 09:57
do you have the salts? if not then I really dont think you should bother because you probably dont want to to crack a 32+ passwod/salt. If you do have the salts then I sure you could write a simple dictionary cracker that adds on the salt at the end. If you need it, I have a simple md5 cracker that you could modify.

:)

_('~')_/ how does it feel to be something on?
Grindordie
Administrator
Software Engineer

Avatar
ZI Guru

Joined: 04.11.2007
Last Seen: 10 year(s) ago
Experience: 1074.3
Points: 1100
#6 RE: crack md5 with salt on October 13 2008 01:09
Well, if you know the salt like scanky said, you can create a dictionary attack/brute forcer to use the same salting algorithm and compare the hashes.

Otherwise, the only way to find the plain text would be to guess the whole plain-text or find a collision.

MD5 has become really insecure.. I've started to use sha-256 to hash stuff.

That's not a bug, that's an unexpected feature

phpFort - light-weight content management system.
Tux
Veteran Member
the killer penguin

Avatar
Professional Analyst

Joined: 03.04.2008
Last Seen: 10 year(s) ago
Experience: 579.08
Points: 585
#7 RE: crack md5 with salt on October 13 2008 22:26
ok, i'm 99% sure this is the code used to make encrypt and authenticate.

Code Highlighting :: Select Code

    $query = 'SELECT `id`, `password`, `gid`'
            . ' FROM `#__users`'
            . ' WHERE username=' . $db->Quote( $credentials['username'] )
            ;
        $db->setQuery( $query );
        $result = $db->loadObject();


        if($result)
        {
            $parts    = explode( ':', $result->password );
            $crypt    = $parts[0];
            $salt    = @$parts[1];
            $testcrypt = JUserHelper::getCryptedPassword($credentials['password'], $salt);

<person i was helping> says:
SELECT ' UNION ALL FROM users?
bigggnick@gmail.com says:
lol
person says:
SELECT 'UNION ALL' FROM users?

LEARN SQL BEFORE ATTEMPTING TO INJECT IT!!!!!!
SirGod
Member
One of Godz

Avatar
Professional Analyst

Joined: 05.09.2008
Last Seen: 10 year(s) ago
Experience: 429.63
Points: 1310
#8 RE: crack md5 with salt on October 28 2008 09:39
Use PasswordsPro

Nothing.
hack4u
Administrator
ZI Owner

Avatar
ZI Guru

Joined: 30.03.2008
Last Seen: 10 year(s) ago
Experience: 19699.95
Points: 1285
#9 RE: crack md5 with salt on October 29 2008 10:55
Quoted from SirGod:
Use PasswordsPro


agreed. its free and can crack damm near everything i put in it :D


Image
Image


Who is watching forums


Users viewing this page: Guests (1)
Users viewing the forum: 0