«
Expand/Collapse
145 items tagged "hash"
Related tags:
tomcat [+],
linux [+],
proof of concept [+],
crackers [+],
ruby [+],
php [+],
hash table [+],
denial [+],
utility [+],
hash values [+],
advanced [+],
txt [+],
xendesktop [+],
vulnerability [+],
sha1 [+],
pwrite [+],
password [+],
md4 [+],
mask [+],
manager [+],
hash functions [+],
disclosure [+],
clamav [+],
citrix [+],
aws [+],
hash collision [+],
xenserver [+],
web security [+],
web [+],
type [+],
table [+],
security appliance [+],
security advisory [+],
router [+],
root user [+],
root [+],
receiver version [+],
rack [+],
mcafee [+],
mandriva linux [+],
mandriva [+],
help [+],
g wireless [+],
email [+],
crack [+],
coredump [+],
collisions [+],
brute force attack [+],
brute force [+],
bit [+],
belkin [+],
Bugs [+],
service vulnerability [+],
denial of service [+],
with [+],
whitepaper [+],
vectors [+],
unhash [+],
tar bz2 [+],
small linux [+],
shellcode [+],
shadow [+],
python [+],
program [+],
poc [+],
perl script [+],
pdf [+],
p network [+],
multi [+],
moaub [+],
md5 hash [+],
libxml [+],
kind [+],
hashes [+],
hashcat [+],
functionality [+],
ed2k [+],
dynpage [+],
cpu [+],
cms systems [+],
cms [+],
apr [+],
Newbie [+],
collision [+],
wpa tkip [+],
wordpress [+],
wlan [+],
vuln [+],
unix c [+],
unix [+],
tuples [+],
traffic [+],
this [+],
there [+],
string [+],
state [+],
stack [+],
solaris [+],
simple [+],
sha [+],
screen [+],
salve [+],
rubinius [+],
remote [+],
receiver [+],
realplayer [+],
read [+],
rainbowcrack [+],
public competition [+],
psk [+],
proxy support [+],
peripherie [+],
paper [+],
pa [+],
oracle [+],
openbsd [+],
online [+],
offline [+],
net [+],
month [+],
mode [+],
maradns [+],
logarithm [+],
list [+],
jruby [+],
jean philippe aumasson [+],
javascript engine [+],
javascript [+],
java [+],
ipad [+],
information disclosure [+],
ike main [+],
ike aggressive [+],
ike [+],
ibmaix [+],
ibm aix [+],
ibm [+],
heap [+],
hash tables [+],
hash md5 [+],
hash algorithm [+],
generator [+],
ftpd [+],
ftp server [+],
finalists [+],
file [+],
fault injection [+],
engine [+],
encryption [+],
des [+],
dei [+],
darknet [+],
darkc [+],
damn [+],
cve [+],
computer [+],
competition [+],
coldfusion [+],
cisco unity [+],
chaos communication congress [+],
carp [+],
cap [+],
calculator version [+],
calculator [+],
cain [+],
bl4ck [+],
bittorrent [+],
attack [+],
asp [+],
appreciated [+],
antenna [+],
angebot [+],
analysor [+],
amazon ec2 [+],
amazon [+],
algoritmo [+],
algorithm [+],
aix [+],
adobe [+],
Wireless [+],
Support [+],
Hardware [+],
Countermeasures [+],
Area [+],
Angolo [+],
3 candidates [+],
gpu [+],
dictionary [+],
apache [+],
oclhashcat [+],
apache tomcat [+]
-
-
20:28
»
Packet Storm Security Recent Files
oclHashcat+ Advanced GPU hash cracking utility that includes the World's fastest md5crypt and phpass crackers and has the first GPGPU-based rule engine. Focuses on highly iterated modern hashes, single dictionary-based attacks, and more. 32-bit version.
-
20:28
»
Packet Storm Security Misc. Files
oclHashcat+ Advanced GPU hash cracking utility that includes the World's fastest md5crypt and phpass crackers and has the first GPGPU-based rule engine. Focuses on highly iterated modern hashes, single dictionary-based attacks, and more. 32-bit version.
-
19:50
»
Packet Storm Security Recent Files
oclHashcat+ Advanced GPU hash cracking utility that includes the World's fastest md5crypt and phpass crackers and has the first GPGPU-based rule engine. Focuses on highly iterated modern hashes, single dictionary-based attacks, and more. 64-bit version.
-
19:50
»
Packet Storm Security Misc. Files
oclHashcat+ Advanced GPU hash cracking utility that includes the World's fastest md5crypt and phpass crackers and has the first GPGPU-based rule engine. Focuses on highly iterated modern hashes, single dictionary-based attacks, and more. 64-bit version.
-
-
21:40
»
SecDocs
Tags:
BitTorrent Event:
Chaos Communication Congress 27th (27C3) 2010 Abstract: Distributed Hash Tables implement Routing and Addressability in large P2P networks. In the Kademlia adaption for Bittorrent a peer's address (NodeID) is to be generated randomly, or more appropriate: arbitrarily. Because randomness isn't verifiable, an implementation can advertise itself with popular NodeIDs or even change them on a per-packet basis. Two issues arise due this design problem: Amplification of UDP traffic Amplification of TCP traffic Anyone with a moderate bandwidth connection can induce DDoS attacks with the BitTorrent cloud. Starting with the prerequisites of BitTorrent, I will outline the importance of tracker-less operation and how Magnet links work. Distributed Hash Tables are explained pertaining to the Kademlia algorithm. It is most interesting how implementations maintain and refresh routing information, allowing a malicious node to become a popular neighbour quickly, and how traffic can be amplified in two ways. I will present packet rate analysis measured during tests on Amazon EC2. In conclusion it is explained how the problem of arbitrary NodeIDs can be avoided if the protocol was to be redesigned. A few words are to be given what client authors can do to alleviate the damage potential of the BitTorrent DHT.
-
-
17:08
»
Packet Storm Security Advisories
McAfee Email and Web Security Appliance versions prior to 5.5 Patch 6, Email and Web Security 5.6 Patch 3, and McAfee Email Gateway 7.0 Patch 1 suffer from a password cracking vulnerability.
-
17:08
»
Packet Storm Security Recent Files
McAfee Email and Web Security Appliance versions prior to 5.5 Patch 6, Email and Web Security 5.6 Patch 3, and McAfee Email Gateway 7.0 Patch 1 suffer from a password cracking vulnerability.
-
17:08
»
Packet Storm Security Misc. Files
McAfee Email and Web Security Appliance versions prior to 5.5 Patch 6, Email and Web Security 5.6 Patch 3, and McAfee Email Gateway 7.0 Patch 1 suffer from a password cracking vulnerability.
-
-
16:06
»
Packet Storm Security Advisories
Mandriva Linux Security Advisory 2012-019 - tables/apr_hash.c in the Apache Portable Runtime library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service via crafted input to an application that maintains a hash table. APR has been upgraded to the latest version which holds many improvements over the previous versions and is not vulnerable to this issue.
-
16:06
»
Packet Storm Security Recent Files
Mandriva Linux Security Advisory 2012-019 - tables/apr_hash.c in the Apache Portable Runtime library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service via crafted input to an application that maintains a hash table. APR has been upgraded to the latest version which holds many improvements over the previous versions and is not vulnerable to this issue.
-
16:06
»
Packet Storm Security Misc. Files
Mandriva Linux Security Advisory 2012-019 - tables/apr_hash.c in the Apache Portable Runtime library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service via crafted input to an application that maintains a hash table. APR has been upgraded to the latest version which holds many improvements over the previous versions and is not vulnerable to this issue.
-
-
6:53
»
Packet Storm Security Exploits
PHP 5.3.x hash collision denial of service proof of concept exploit written in Python. It generates the payload on the fly and sends it to the server.
-
6:53
»
Packet Storm Security Recent Files
PHP 5.3.x hash collision denial of service proof of concept exploit written in Python. It generates the payload on the fly and sends it to the server.
-
6:53
»
Packet Storm Security Misc. Files
PHP 5.3.x hash collision denial of service proof of concept exploit written in Python. It generates the payload on the fly and sends it to the server.
-
-
9:49
»
Packet Storm Security Advisories
Most hash functions used in hash table implementations can be broken faster than by using brute-force techniques (which is feasible for hash functions with 32 bit output, but very expensive for 64 bit functions) by using one of two "tricks": equivalent substrings or a meet-in-the-middle attack.
-
9:49
»
Packet Storm Security Recent Files
Most hash functions used in hash table implementations can be broken faster than by using brute-force techniques (which is feasible for hash functions with 32 bit output, but very expensive for 64 bit functions) by using one of two "tricks": equivalent substrings or a meet-in-the-middle attack.
-
9:49
»
Packet Storm Security Misc. Files
Most hash functions used in hash table implementations can be broken faster than by using brute-force techniques (which is feasible for hash functions with 32 bit output, but very expensive for 64 bit functions) by using one of two "tricks": equivalent substrings or a meet-in-the-middle attack.
-
-
18:44
»
Carnal0wnage
There hasnt been much in the way of updates on breaking into VPN servers that have aggressive mode enabled.
ike-scan is probably still your best bet.
If you have no idea what i'm talking about go read this:
http://www.sersc.org/journals/IJAST/vol8/2.pdf and
http://www.radarhack.com/dir/papers/Scanning_ike_with_ikescan.pdf
In IKE Aggressive mode the authentication hash based on a preshared key (PSK) is transmitted as response to the initial packet of a vpn client that wants to establish an IPSec Tunnel (Hash_R). This hash is not encrypted. It's possible to capture these packets using a sniffer, for example tcpdump and start dictionary or brute force attack against this hash to recover the PSK.
This attack only works in IKE aggressive mode because in IKE Main Mode the hash is already encrypted. Based on such facts IKE aggressive mode is not very secure.
It looks like this:
$ sudo ike-scan 192.168.207.134
Starting ike-scan 1.9 with 1 hosts (http://www.nta-monitor.com/tools/ike-scan/)
192.168.207.134 Notify message 14 (NO-PROPOSAL-CHOSEN) HDR=(CKY-R=f320d682d5c73797)
Ending ike-scan 1.9: 1 hosts scanned in 0.096 seconds (10.37 hosts/sec).
0 returned handshake; 1 returned notify
$ sudo ike-scan -A 192.168.207.134
Starting ike-scan 1.9 with 1 hosts (http://www.nta-monitor.com/tools/ikescan/)
192.168.207.134 Aggressive Mode Handshake returned HDR=(CKY-R=f320d6XXXXXXXX) SA=(Enc=3DES Hash=MD5 Group=2:modp1024 Auth=PSK LifeType=Seconds LifeDuration=28800) VID=12f5f28cXXXXXXXXXXXXXXX (Cisco Unity) VID=afcad71368a1XXXXXXXXXXXXXXX(Dead Peer Detection v1.0) VID=06e7719XXXXXXXXXXXXXXXXXXXXXX VID=090026XXXXXXXXXX (XAUTH) KeyExchange(128 bytes) ID(Type=ID_IPV4_ADDR, Value=192.168.207.134) Nonce(20 bytes) Hash(16 bytes)
To save with some output:
$ sudo ike-scan -A 192.168.207.134 --id=myid -P192-168-207-134key
Once you have you psk file to crack you're stuck with two options psk-crack and cain
psk-crack is fairly rudamentary
to brute force:
$psk-crack -b 5 192-168-207-134key
Running in brute-force cracking mode
Brute force with 36 chars up to length 5 will take up to 60466176 iterations
no match found for MD5 hash 5c178d[SNIP]
Ending psk-crack: 60466176 iterations in 138.019 seconds (438099.56 iterations/sec)
Default is charset is "0123456789abcdefghijklmnopqrstuvwxyz" can be changed with --charset=
$ psk-crack -b 5 --charset="01233456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz" 192-168-207-134key
Running in brute-force cracking modde
Brute force with 63 chars up to length 5 will take up to 992436543 iterations
To dictionary attack:
$psk-crack -d /path/to/dictionary 192-168-207-134key
Running in dictionary cracking mode
no match found for MD5 hash 5c178d[SNIP]
Ending psk-crack: 14344876 iterations in 33.400 seconds (429483.14 iterations/sec)
You may find yourself wanting a bit more flexibility or options during bruteforcing or dictionary attacking (i.e. character substition). For this you'll need to use
Cain. The problem I ran in to was Cain is a Windows tool and ike-scan is *nix. I couldnt get the windows tool that is floating around to work. Solution...run in vmware and have Cain sniff on your VMware interface. The PSK should show up in passwords of the sniffer tab, then you can select and "send to cracker". Its slow as hell, but more options than psk-crack.


-
-
15:45
»
Packet Storm Security Recent Files
oclHashcat+ Advanced GPU hash cracking utility that includes the World's fastest md5crypt and phpass crackers and has the first GPGPU-based rule engine. Focuses on highly iterated modern hashes, single dictionary-based attacks, and more. Linux and Windows binaries are included.
-
15:45
»
Packet Storm Security Misc. Files
oclHashcat+ Advanced GPU hash cracking utility that includes the World's fastest md5crypt and phpass crackers and has the first GPGPU-based rule engine. Focuses on highly iterated modern hashes, single dictionary-based attacks, and more. Linux and Windows binaries are included.
-
15:43
»
Packet Storm Security Recent Files
oclHashcat-lite Advanced GPU hash cracking utility that includes the World's fastest MD4, MD5, SHA1, and SHA256 cracker. It supports up to 16 GPUs and include binaries for both Linux and Windows.
-
15:43
»
Packet Storm Security Misc. Files
oclHashcat-lite Advanced GPU hash cracking utility that includes the World's fastest MD4, MD5, SHA1, and SHA256 cracker. It supports up to 16 GPUs and include binaries for both Linux and Windows.
-
15:43
»
Packet Storm Security Recent Files
oclHashcat GPU hash cracking utility that has multi-GPU and multi-hash support. It supports dictionary-based and mask-attacks for hybrid cracking. Linux and Windows binaries are included.
-
15:43
»
Packet Storm Security Misc. Files
oclHashcat GPU hash cracking utility that has multi-GPU and multi-hash support. It supports dictionary-based and mask-attacks for hybrid cracking. Linux and Windows binaries are included.
-
-
15:08
»
SecDocs
Authors:
Jean-Philippe Aumasson Tags:
cryptography alghoritm Event:
Hashdays 2010 Abstract: After the AES Competition in the late 90s, the US NIST is now running a public competition to select the future cryptographic hash SHA-3. In this talk, we’ll present the motivations behind this initiative, with a focus on the only Swiss candidate BLAKE, which is one of the few candidates left in the competition. Then we’ll describe new results on one of the SHA-3 candidates, and we'll discuss the applicability of fault injection attacks to the HMAC construction. Finally, we’ll argue that SHA-3 is not the end of the road, since SHA-3 candidates are all software-oriented algorithms too demanding for constrainted environments, and we’ll present a proposal for a lightweight hash (previously presented at CHES 2010).
-
-
8:12
»
Packet Storm Security Recent Files
oclHashcat-lite Advanced GPU hash cracking utility that includes the World's fastest MD4, MD5, SHA1, and SHA256 cracker. It supports up to 16 GPUs and include binaries for both Linux and Windows.
-
8:12
»
Packet Storm Security Misc. Files
oclHashcat-lite Advanced GPU hash cracking utility that includes the World's fastest MD4, MD5, SHA1, and SHA256 cracker. It supports up to 16 GPUs and include binaries for both Linux and Windows.
-
-
16:04
»
Packet Storm Security Recent Files
oclHashcat GPU hash cracking utility that has multi-GPU and multi-hash support. It supports dictionary-based and mask-attacks for hybrid cracking. Linux and Windows binaries are included.
-
16:04
»
Packet Storm Security Misc. Files
oclHashcat GPU hash cracking utility that has multi-GPU and multi-hash support. It supports dictionary-based and mask-attacks for hybrid cracking. Linux and Windows binaries are included.
-
15:09
»
Packet Storm Security Recent Files
oclHashcat+ Advanced GPU hash cracking utility that includes the World's fastest md5crypt and phpass crackers and has the first GPGPU-based rule engine. Focuses on highly iterated modern hashes, single dictionary-based attacks, and more. Linux and Windows binaries are included.
-
15:09
»
Packet Storm Security Misc. Files
oclHashcat+ Advanced GPU hash cracking utility that includes the World's fastest md5crypt and phpass crackers and has the first GPGPU-based rule engine. Focuses on highly iterated modern hashes, single dictionary-based attacks, and more. Linux and Windows binaries are included.
-
-
22:01
»
Packet Storm Security Recent Files
Month Of Abysssec Undisclosed Bugs - DynPage versions 1.0 and below suffer from local file disclosure and administrative hash disclosure vulnerabilities.
-
22:00
»
Packet Storm Security Exploits
Month Of Abysssec Undisclosed Bugs - DynPage versions 1.0 and below suffer from local file disclosure and administrative hash disclosure vulnerabilities.
-
22:00
»
Packet Storm Security Advisories
Month Of Abysssec Undisclosed Bugs - DynPage versions 1.0 and below suffer from local file disclosure and administrative hash disclosure vulnerabilities.
-
-
11:40
»
remote-exploit & backtrack
Salve a tutti!
Sono riuscito ad ottenere un HASH e una password in chiaro, credo che siano in DES(UNIX). C'è un modo per ricavare l'algoritmo di hashing?
Grazie,
Fandonius
-
-
21:23
»
remote-exploit & backtrack
Hello,
where does ipad keep its screen unlock paswword hash in file system?
thanks
-
-
13:35
»
Packet Storm Security Exploits
AIX 5l with FTP server remote root hash disclosure exploit. Creates a coredump including the root user hash from /etc/security/passwd. This is the second version that was written to be more portable between hosts.
-
19:02
»
Packet Storm Security Exploits
AIX5l with FTP server remote root hash disclosure exploit. Creates a coredump including the root user hash from /etc/security/passwd.
-
-
1:00
»
Packet Storm Security Tools
UnHash is a program that performs a brute force attack against a given hash. The hash can be MD5 or SHA1, and the program will auto-detect which one is given.
-
1:00
»
Packet Storm Security Recent Files
UnHash is a program that performs a brute force attack against a given hash. The hash can be MD5 or SHA1, and the program will auto-detect which one is given.
-
-
16:42
»
remote-exploit & backtrack
I set up a wireless network with WPA/TKIP encriptation to try to crack it.
I got the hash in a .cap file. I'd like to know if I can get the hash out of the cap file. I know I can run aircrack or cowpatty on the cap file with a wordlist or rainbow table but I'm curious about how to find the hash. I also would like to know if I can try to crack it like it was a MD5 hash.
Thanks for the attention.
-
-
5:55
»
remote-exploit & backtrack
Ist das ein gutes Angebot?
hxxp://cgi.ebay.de/ALFA-NETWORK-AWUS036H-1000mW-WLAN-USB-5dBi-antenna_W0QQitemZ250559645826QQcmdZViewItemQQptZDE _Computer_Peripherie_Netzwerk?hash=item3a5684c882
-
-
15:30
»
SecDocs
Tags:
cryptography Abstract: In this paper, we study the existence of multicollisions in it- erated hash functions. We show that finding multicollisions, i.e. r-tuples of messages that all hash to the same value, is not much harder than finding ordinary collisions, i.e. pairs of messages, even for extremely large values of r. More precisely, the ratio of the complexities of the attacks is approximately equal to the logarithm of r. Then, using large multi- collisions as a tool, we solve a long standing open problem and prove that concatenating the results of several iterated hash functions in or- der to build a larger one does not yield a secure construction. We also discuss the potential impact of our attack on several published schemes. Quite surprisingly, for subtle reasons, the schemes we study happen to be immune to our attack.