Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.advocacy > #350990 > unrolled thread
| Started by | owl <owl@rooftop.invalid> |
|---|---|
| First post | 2016-04-20 15:10 +0000 |
| Last post | 2016-04-21 16:26 +0000 |
| Articles | 16 on this page of 36 — 6 participants |
Back to article view | Back to comp.os.linux.advocacy
LOL underestimated owl <owl@rooftop.invalid> - 2016-04-20 15:10 +0000
Re: LOL underestimated vallor <vallor@cultnix.org> - 2016-04-20 16:55 +0000
Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-20 17:25 +0000
Re: LOL underestimated vallor <vallor@cultnix.org> - 2016-04-20 18:45 +0000
Re: LOL underestimated vallor <vallor@cultnix.org> - 2016-04-20 18:47 +0000
Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-20 21:05 +0000
Re: LOL underestimated vallor <vallor@cultnix.org> - 2016-04-25 19:07 +0000
Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-25 21:16 +0000
Re: LOL underestimated Melzzzzz <mel@zzzzz.com> - 2016-04-20 20:51 +0200
Re: LOL underestimated Melzzzzz <mel@zzzzz.com> - 2016-04-20 19:19 +0200
Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-20 17:34 +0000
Re: LOL underestimated Melzzzzz <mel@zzzzz.com> - 2016-04-20 20:31 +0200
Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-20 21:13 +0000
Re: LOL underestimated Melzzzzz <mel@zzzzz.com> - 2016-04-20 23:20 +0200
Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-20 21:29 +0000
Re: LOL underestimated Me Sham <osirus47@yahoo.com> - 2016-04-20 14:33 -0700
Re: LOL underestimated Melzzzzz <mel@zzzzz.com> - 2016-04-20 23:58 +0200
Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-20 22:04 +0000
Re: LOL underestimated Melzzzzz <mel@zzzzz.com> - 2016-04-20 23:25 +0200
Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-20 21:41 +0000
Re: LOL underestimated Peter Köhlmann <peter-koehlmann@t-online.de> - 2016-04-20 23:50 +0200
Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-20 22:06 +0000
Re: LOL underestimated Peter Köhlmann <peter-koehlmann@t-online.de> - 2016-04-21 08:54 +0200
Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-21 17:12 +0000
Re: LOL underestimated Melzzzzz <mel@zzzzz.com> - 2016-04-20 23:50 +0200
Re: LOL underestimated Peter Köhlmann <peter-koehlmann@t-online.de> - 2016-04-20 23:51 +0200
Re: LOL underestimated Melzzzzz <mel@zzzzz.com> - 2016-04-20 23:59 +0200
Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-20 22:10 +0000
Re: LOL underestimated Melzzzzz <mel@zzzzz.com> - 2016-04-21 00:11 +0200
Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-20 22:19 +0000
Re: LOL underestimated Melzzzzz <mel@zzzzz.com> - 2016-04-21 00:57 +0200
Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-21 00:07 +0000
Re: LOL underestimated DFS <nospam@dfs.com> - 2016-04-20 23:17 -0400
Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-21 03:49 +0000
Re: LOL underestimated DFS <nospam@dfs.com> - 2016-04-21 10:27 -0400
Re: LOL underestimated owl <owl@rooftop.invalid> - 2016-04-21 16:26 +0000
Page 2 of 2 — ← Prev page 1 [2]
| From | Peter Köhlmann <peter-koehlmann@t-online.de> |
|---|---|
| Date | 2016-04-20 23:50 +0200 |
| Message-ID | <nf8tc6$f5c$1@dont-email.me> |
| In reply to | #351063 |
owl wrote: > Melzzzzz <mel@zzzzz.com> wrote: >> On Wed, 20 Apr 2016 21:13:16 +0000 (UTC) >> owl <owl@rooftop.invalid> wrote: >> >>> Melzzzzz <mel@zzzzz.com> wrote: >>> > On Wed, 20 Apr 2016 17:34:37 +0000 (UTC) >>> > owl <owl@rooftop.invalid> wrote: >>> > >>> >> >>> >> I'm simultaneously running an attack on a particular hash over the >>> >> entire address space (those eight small windows in the vid). >>> >> >>> > >>> > https://eprint.iacr.org/2006/105 >>> > Tunnels in Hash Functions: MD5 Collisions Within a Minute >>> >>> Unless I'm misunderstanding things, that's just generating collision >>> pairs. Correct me if I'm wrong, but I assume that all attacks >>> against a hash still require a dictionary of hashes (which is what >>> I'm generating). >>> >> >> If you find collision of particular length, you have probable >> solution... > > Length of what? > Can you give me a layman's executive summary of how the described > approach can reveal the original input given only the known hash? There is none. The MD5 collisions just give another set of data which will return the same MD5 hash. You don't get a peek at the original data For that very reason linux packages protected by MD5 are still safe, because a "forged" package would not be runable in any way. There is no way to alter a program (with the intent of introducing malware) and expecting to get the original MD5 hash. All the supercomputers existing don't have enough time to compute that before crumbling to rust and sand
[toc] | [prev] | [next] | [standalone]
| From | owl <owl@rooftop.invalid> |
|---|---|
| Date | 2016-04-20 22:06 +0000 |
| Message-ID | <ghjdu03.a09uh3@rooftop.invalid> |
| In reply to | #351065 |
Peter Köhlmann <peter-koehlmann@t-online.de> wrote: > owl wrote: > >> Melzzzzz <mel@zzzzz.com> wrote: >>> On Wed, 20 Apr 2016 21:13:16 +0000 (UTC) >>> owl <owl@rooftop.invalid> wrote: >>> >>>> Melzzzzz <mel@zzzzz.com> wrote: >>>> > On Wed, 20 Apr 2016 17:34:37 +0000 (UTC) >>>> > owl <owl@rooftop.invalid> wrote: >>>> > >>>> >> >>>> >> I'm simultaneously running an attack on a particular hash over the >>>> >> entire address space (those eight small windows in the vid). >>>> >> >>>> > >>>> > https://eprint.iacr.org/2006/105 >>>> > Tunnels in Hash Functions: MD5 Collisions Within a Minute >>>> >>>> Unless I'm misunderstanding things, that's just generating collision >>>> pairs. Correct me if I'm wrong, but I assume that all attacks >>>> against a hash still require a dictionary of hashes (which is what >>>> I'm generating). >>>> >>> >>> If you find collision of particular length, you have probable >>> solution... >> >> Length of what? >> Can you give me a layman's executive summary of how the described >> approach can reveal the original input given only the known hash? > > There is none. The MD5 collisions just give another set of data which will > return the same MD5 hash. You don't get a peek at the original data > > For that very reason linux packages protected by MD5 are still safe, because > a "forged" package would not be runable in any way. There is no way to alter > a program (with the intent of introducing malware) and expecting to get the > original MD5 hash. All the supercomputers existing don't have enough time to > compute that before crumbling to rust and sand So would you say that the approach I'm taking, i.e. a lookup table, is the best approach?
[toc] | [prev] | [next] | [standalone]
| From | Peter Köhlmann <peter-koehlmann@t-online.de> |
|---|---|
| Date | 2016-04-21 08:54 +0200 |
| Message-ID | <nf9t9g$6n5$1@dont-email.me> |
| In reply to | #351075 |
owl wrote: > Peter Köhlmann <peter-koehlmann@t-online.de> wrote: >> owl wrote: >> >>> Melzzzzz <mel@zzzzz.com> wrote: >>>> On Wed, 20 Apr 2016 21:13:16 +0000 (UTC) >>>> owl <owl@rooftop.invalid> wrote: >>>> >>>>> Melzzzzz <mel@zzzzz.com> wrote: >>>>> > On Wed, 20 Apr 2016 17:34:37 +0000 (UTC) >>>>> > owl <owl@rooftop.invalid> wrote: >>>>> > >>>>> >> >>>>> >> I'm simultaneously running an attack on a particular hash over the >>>>> >> entire address space (those eight small windows in the vid). >>>>> >> >>>>> > >>>>> > https://eprint.iacr.org/2006/105 >>>>> > Tunnels in Hash Functions: MD5 Collisions Within a Minute >>>>> >>>>> Unless I'm misunderstanding things, that's just generating collision >>>>> pairs. Correct me if I'm wrong, but I assume that all attacks >>>>> against a hash still require a dictionary of hashes (which is what >>>>> I'm generating). >>>>> >>>> >>>> If you find collision of particular length, you have probable >>>> solution... >>> >>> Length of what? >>> Can you give me a layman's executive summary of how the described >>> approach can reveal the original input given only the known hash? >> >> There is none. The MD5 collisions just give another set of data which >> will return the same MD5 hash. You don't get a peek at the original data >> >> For that very reason linux packages protected by MD5 are still safe, >> because a "forged" package would not be runable in any way. There is no >> way to alter a program (with the intent of introducing malware) and >> expecting to get the original MD5 hash. All the supercomputers existing >> don't have enough time to compute that before crumbling to rust and sand > > So would you say that the approach I'm taking, i.e. a lookup table, is > the best approach? Maybe It /might/ be that it is possible for data of very small size (for example IP addresses) to generate collisions and compare the resulting IP. Since those are restricted to a well defined format and range (in IP4 at least, IP6 is already much larger) it may be possible, although I doubt that it is worth the expense in time
[toc] | [prev] | [next] | [standalone]
| From | owl <owl@rooftop.invalid> |
|---|---|
| Date | 2016-04-21 17:12 +0000 |
| Message-ID | <fhjgoe03.afaa3@rooftop.invalid> |
| In reply to | #351114 |
Peter Köhlmann <peter-koehlmann@t-online.de> wrote: > owl wrote: > >> Peter Köhlmann <peter-koehlmann@t-online.de> wrote: >>> owl wrote: >>> >>>> Melzzzzz <mel@zzzzz.com> wrote: >>>>> On Wed, 20 Apr 2016 21:13:16 +0000 (UTC) >>>>> owl <owl@rooftop.invalid> wrote: >>>>> >>>>>> Melzzzzz <mel@zzzzz.com> wrote: >>>>>> > On Wed, 20 Apr 2016 17:34:37 +0000 (UTC) >>>>>> > owl <owl@rooftop.invalid> wrote: >>>>>> > >>>>>> >> >>>>>> >> I'm simultaneously running an attack on a particular hash over the >>>>>> >> entire address space (those eight small windows in the vid). >>>>>> >> >>>>>> > >>>>>> > https://eprint.iacr.org/2006/105 >>>>>> > Tunnels in Hash Functions: MD5 Collisions Within a Minute >>>>>> >>>>>> Unless I'm misunderstanding things, that's just generating collision >>>>>> pairs. Correct me if I'm wrong, but I assume that all attacks >>>>>> against a hash still require a dictionary of hashes (which is what >>>>>> I'm generating). >>>>>> >>>>> >>>>> If you find collision of particular length, you have probable >>>>> solution... >>>> >>>> Length of what? >>>> Can you give me a layman's executive summary of how the described >>>> approach can reveal the original input given only the known hash? >>> >>> There is none. The MD5 collisions just give another set of data which >>> will return the same MD5 hash. You don't get a peek at the original data >>> >>> For that very reason linux packages protected by MD5 are still safe, >>> because a "forged" package would not be runable in any way. There is no >>> way to alter a program (with the intent of introducing malware) and >>> expecting to get the original MD5 hash. All the supercomputers existing >>> don't have enough time to compute that before crumbling to rust and sand >> >> So would you say that the approach I'm taking, i.e. a lookup table, is >> the best approach? > > Maybe > > It /might/ be that it is possible for data of very small size (for example > IP addresses) to generate collisions and compare the resulting IP. Since > those are restricted to a well defined format and range (in IP4 at least, > IP6 is already much larger) it may be possible, although I doubt that it is > worth the expense in time I assume you're talking about the algorithm Melzzzzz mentioned. I take it that given the hash, the algorithm would take a dictionary of small strings and determine colliding values and hope that one of them was an IP address? I checked for the source code that's at the site Melzzzz linked. One was Win32 and required conio.h Another was c++ and failed to compile because it couldn't find some boost "filesystem" file. I installed libboost-filesystem1.55.0 and still got the error. I'm mainly interested in how it works, not so much from a mathematical angle as from the standpoint of the user. IOW, what prerequisites do you need in terms of dictionary file, etc.
[toc] | [prev] | [next] | [standalone]
| From | Melzzzzz <mel@zzzzz.com> |
|---|---|
| Date | 2016-04-20 23:50 +0200 |
| Message-ID | <20160420235021.4a95a738@maxa-pc> |
| In reply to | #351063 |
On Wed, 20 Apr 2016 21:41:51 +0000 (UTC) owl <owl@rooftop.invalid> wrote: > Melzzzzz <mel@zzzzz.com> wrote: > > On Wed, 20 Apr 2016 21:13:16 +0000 (UTC) > > owl <owl@rooftop.invalid> wrote: > > > >> Melzzzzz <mel@zzzzz.com> wrote: > >> > On Wed, 20 Apr 2016 17:34:37 +0000 (UTC) > >> > owl <owl@rooftop.invalid> wrote: > >> > > >> >> > >> >> I'm simultaneously running an attack on a particular hash over > >> >> the entire address space (those eight small windows in the vid). > >> >> > >> > > >> > https://eprint.iacr.org/2006/105 > >> > Tunnels in Hash Functions: MD5 Collisions Within a Minute > >> > >> Unless I'm misunderstanding things, that's just generating > >> collision pairs. Correct me if I'm wrong, but I assume that all > >> attacks against a hash still require a dictionary of hashes (which > >> is what I'm generating). > >> > > > > If you find collision of particular length, you have probable > > solution... > > Length of what? > Can you give me a layman's executive summary of how the described > approach can reveal the original input given only the known hash? > look, this algo quickly finds out source of particular hash value. Got it?
[toc] | [prev] | [next] | [standalone]
| From | Peter Köhlmann <peter-koehlmann@t-online.de> |
|---|---|
| Date | 2016-04-20 23:51 +0200 |
| Message-ID | <nf8tf0$f5c$2@dont-email.me> |
| In reply to | #351066 |
Melzzzzz wrote: > On Wed, 20 Apr 2016 21:41:51 +0000 (UTC) > owl <owl@rooftop.invalid> wrote: > >> Melzzzzz <mel@zzzzz.com> wrote: >> > On Wed, 20 Apr 2016 21:13:16 +0000 (UTC) >> > owl <owl@rooftop.invalid> wrote: >> > >> >> Melzzzzz <mel@zzzzz.com> wrote: >> >> > On Wed, 20 Apr 2016 17:34:37 +0000 (UTC) >> >> > owl <owl@rooftop.invalid> wrote: >> >> > >> >> >> >> >> >> I'm simultaneously running an attack on a particular hash over >> >> >> the entire address space (those eight small windows in the vid). >> >> >> >> >> > >> >> > https://eprint.iacr.org/2006/105 >> >> > Tunnels in Hash Functions: MD5 Collisions Within a Minute >> >> >> >> Unless I'm misunderstanding things, that's just generating >> >> collision pairs. Correct me if I'm wrong, but I assume that all >> >> attacks against a hash still require a dictionary of hashes (which >> >> is what I'm generating). >> >> >> > >> > If you find collision of particular length, you have probable >> > solution... >> >> Length of what? >> Can you give me a layman's executive summary of how the described >> approach can reveal the original input given only the known hash? >> > > look, this algo quickly finds out source of particular hash value. Got > it? Yes. For data which has nothing at all to do with the original data. Which makes it sort of pointless
[toc] | [prev] | [next] | [standalone]
| From | Melzzzzz <mel@zzzzz.com> |
|---|---|
| Date | 2016-04-20 23:59 +0200 |
| Message-ID | <20160420235954.361bcf42@maxa-pc> |
| In reply to | #351068 |
On Wed, 20 Apr 2016 23:51:39 +0200 Peter Köhlmann <peter-koehlmann@t-online.de> wrote: > Melzzzzz wrote: > > > On Wed, 20 Apr 2016 21:41:51 +0000 (UTC) > > owl <owl@rooftop.invalid> wrote: > > > >> Melzzzzz <mel@zzzzz.com> wrote: > >> > On Wed, 20 Apr 2016 21:13:16 +0000 (UTC) > >> > owl <owl@rooftop.invalid> wrote: > >> > > >> >> Melzzzzz <mel@zzzzz.com> wrote: > >> >> > On Wed, 20 Apr 2016 17:34:37 +0000 (UTC) > >> >> > owl <owl@rooftop.invalid> wrote: > >> >> > > >> >> >> > >> >> >> I'm simultaneously running an attack on a particular hash > >> >> >> over the entire address space (those eight small windows in > >> >> >> the vid). > >> >> > > >> >> > https://eprint.iacr.org/2006/105 > >> >> > Tunnels in Hash Functions: MD5 Collisions Within a Minute > >> >> > >> >> Unless I'm misunderstanding things, that's just generating > >> >> collision pairs. Correct me if I'm wrong, but I assume that all > >> >> attacks against a hash still require a dictionary of hashes > >> >> (which is what I'm generating). > >> >> > >> > > >> > If you find collision of particular length, you have probable > >> > solution... > >> > >> Length of what? > >> Can you give me a layman's executive summary of how the described > >> approach can reveal the original input given only the known hash? > >> > > > > look, this algo quickly finds out source of particular hash value. > > Got it? > > Yes. For data which has nothing at all to do with the original data. > Which makes it sort of pointless If length is known there is finite number of combinations. I really doubt you can get two different ip addresses for same md5 hash...
[toc] | [prev] | [next] | [standalone]
| From | owl <owl@rooftop.invalid> |
|---|---|
| Date | 2016-04-20 22:10 +0000 |
| Message-ID | <ghjdi03.a0h3b4428@rooftop.invalid> |
| In reply to | #351071 |
Melzzzzz <mel@zzzzz.com> wrote: > On Wed, 20 Apr 2016 23:51:39 +0200 > Peter Köhlmann <peter-koehlmann@t-online.de> wrote: > >> Melzzzzz wrote: >> >> > On Wed, 20 Apr 2016 21:41:51 +0000 (UTC) >> > owl <owl@rooftop.invalid> wrote: >> > >> >> Melzzzzz <mel@zzzzz.com> wrote: >> >> > On Wed, 20 Apr 2016 21:13:16 +0000 (UTC) >> >> > owl <owl@rooftop.invalid> wrote: >> >> > >> >> >> Melzzzzz <mel@zzzzz.com> wrote: >> >> >> > On Wed, 20 Apr 2016 17:34:37 +0000 (UTC) >> >> >> > owl <owl@rooftop.invalid> wrote: >> >> >> > >> >> >> >> >> >> >> >> I'm simultaneously running an attack on a particular hash >> >> >> >> over the entire address space (those eight small windows in >> >> >> >> the vid). >> >> >> > >> >> >> > https://eprint.iacr.org/2006/105 >> >> >> > Tunnels in Hash Functions: MD5 Collisions Within a Minute >> >> >> >> >> >> Unless I'm misunderstanding things, that's just generating >> >> >> collision pairs. Correct me if I'm wrong, but I assume that all >> >> >> attacks against a hash still require a dictionary of hashes >> >> >> (which is what I'm generating). >> >> >> >> >> > >> >> > If you find collision of particular length, you have probable >> >> > solution... >> >> >> >> Length of what? >> >> Can you give me a layman's executive summary of how the described >> >> approach can reveal the original input given only the known hash? >> >> >> > >> > look, this algo quickly finds out source of particular hash value. >> > Got it? >> >> Yes. For data which has nothing at all to do with the original data. >> Which makes it sort of pointless > > If length is known there is finite number of combinations. I really > doubt you can get two different ip addresses for same md5 hash... > Which means that to derive an IP address knowing only its hash, it becomes necessary to generate hashes for all possible IP addresses for comparison with the given hash, right?
[toc] | [prev] | [next] | [standalone]
| From | Melzzzzz <mel@zzzzz.com> |
|---|---|
| Date | 2016-04-21 00:11 +0200 |
| Message-ID | <20160421001155.68313d39@maxa-pc> |
| In reply to | #351077 |
On Wed, 20 Apr 2016 22:10:12 +0000 (UTC) owl <owl@rooftop.invalid> wrote: > Melzzzzz <mel@zzzzz.com> wrote: > > On Wed, 20 Apr 2016 23:51:39 +0200 > > Peter Köhlmann <peter-koehlmann@t-online.de> wrote: > > > >> Melzzzzz wrote: > >> > >> > On Wed, 20 Apr 2016 21:41:51 +0000 (UTC) > >> > owl <owl@rooftop.invalid> wrote: > >> > > >> >> Melzzzzz <mel@zzzzz.com> wrote: > >> >> > On Wed, 20 Apr 2016 21:13:16 +0000 (UTC) > >> >> > owl <owl@rooftop.invalid> wrote: > >> >> > > >> >> >> Melzzzzz <mel@zzzzz.com> wrote: > >> >> >> > On Wed, 20 Apr 2016 17:34:37 +0000 (UTC) > >> >> >> > owl <owl@rooftop.invalid> wrote: > >> >> >> > > >> >> >> >> > >> >> >> >> I'm simultaneously running an attack on a particular hash > >> >> >> >> over the entire address space (those eight small windows > >> >> >> >> in the vid). > >> >> >> > > >> >> >> > https://eprint.iacr.org/2006/105 > >> >> >> > Tunnels in Hash Functions: MD5 Collisions Within a > >> >> >> > Minute > >> >> >> > >> >> >> Unless I'm misunderstanding things, that's just generating > >> >> >> collision pairs. Correct me if I'm wrong, but I assume that > >> >> >> all attacks against a hash still require a dictionary of > >> >> >> hashes (which is what I'm generating). > >> >> >> > >> >> > > >> >> > If you find collision of particular length, you have probable > >> >> > solution... > >> >> > >> >> Length of what? > >> >> Can you give me a layman's executive summary of how the > >> >> described approach can reveal the original input given only the > >> >> known hash? > >> > > >> > look, this algo quickly finds out source of particular hash > >> > value. Got it? > >> > >> Yes. For data which has nothing at all to do with the original > >> data. Which makes it sort of pointless > > > > If length is known there is finite number of combinations. I really > > doubt you can get two different ip addresses for same md5 hash... > > > > Which means that to derive an IP address knowing only its hash, it > becomes necessary to generate hashes for all possible IP addresses > for comparison with the given hash, right? > No, search for collisions of particular length. I didn't look up program but it is only useful with known source length, so I guess if you can limit solution on this algorihtm you can quickly find you ip address.
[toc] | [prev] | [next] | [standalone]
| From | owl <owl@rooftop.invalid> |
|---|---|
| Date | 2016-04-20 22:19 +0000 |
| Message-ID | <hjgda0.jkga9@rooftop.invalid> |
| In reply to | #351078 |
Melzzzzz <mel@zzzzz.com> wrote: > On Wed, 20 Apr 2016 22:10:12 +0000 (UTC) > owl <owl@rooftop.invalid> wrote: > >> Melzzzzz <mel@zzzzz.com> wrote: >> > On Wed, 20 Apr 2016 23:51:39 +0200 >> > Peter Köhlmann <peter-koehlmann@t-online.de> wrote: >> > >> >> Melzzzzz wrote: >> >> >> >> > On Wed, 20 Apr 2016 21:41:51 +0000 (UTC) >> >> > owl <owl@rooftop.invalid> wrote: >> >> > >> >> >> Melzzzzz <mel@zzzzz.com> wrote: >> >> >> > On Wed, 20 Apr 2016 21:13:16 +0000 (UTC) >> >> >> > owl <owl@rooftop.invalid> wrote: >> >> >> > >> >> >> >> Melzzzzz <mel@zzzzz.com> wrote: >> >> >> >> > On Wed, 20 Apr 2016 17:34:37 +0000 (UTC) >> >> >> >> > owl <owl@rooftop.invalid> wrote: >> >> >> >> > >> >> >> >> >> >> >> >> >> >> I'm simultaneously running an attack on a particular hash >> >> >> >> >> over the entire address space (those eight small windows >> >> >> >> >> in the vid). >> >> >> >> > >> >> >> >> > https://eprint.iacr.org/2006/105 >> >> >> >> > Tunnels in Hash Functions: MD5 Collisions Within a >> >> >> >> > Minute >> >> >> >> >> >> >> >> Unless I'm misunderstanding things, that's just generating >> >> >> >> collision pairs. Correct me if I'm wrong, but I assume that >> >> >> >> all attacks against a hash still require a dictionary of >> >> >> >> hashes (which is what I'm generating). >> >> >> >> >> >> >> > >> >> >> > If you find collision of particular length, you have probable >> >> >> > solution... >> >> >> >> >> >> Length of what? >> >> >> Can you give me a layman's executive summary of how the >> >> >> described approach can reveal the original input given only the >> >> >> known hash? >> >> > >> >> > look, this algo quickly finds out source of particular hash >> >> > value. Got it? >> >> >> >> Yes. For data which has nothing at all to do with the original >> >> data. Which makes it sort of pointless >> > >> > If length is known there is finite number of combinations. I really >> > doubt you can get two different ip addresses for same md5 hash... >> > >> >> Which means that to derive an IP address knowing only its hash, it >> becomes necessary to generate hashes for all possible IP addresses >> for comparison with the given hash, right? >> > > No, search for collisions of particular length. I didn't look up > program but it is only useful with known source length, so I guess if > you can limit solution on this algorihtm you can quickly find you ip > address. > Isn't that a contradiction of what you just said? "I really doubt that you can get two different ip addresses for the same md5 hash". The definition of a collision is that the same hash is generated by two different inputs. I'm not trying to be difficult here, Melzzzzz. I just don't understand how collision generation is relevant to the problem.
[toc] | [prev] | [next] | [standalone]
| From | Melzzzzz <mel@zzzzz.com> |
|---|---|
| Date | 2016-04-21 00:57 +0200 |
| Message-ID | <20160421005714.43d640ba@maxa-pc> |
| In reply to | #351079 |
On Wed, 20 Apr 2016 22:19:04 +0000 (UTC) owl <owl@rooftop.invalid> wrote: > Melzzzzz <mel@zzzzz.com> wrote: > > On Wed, 20 Apr 2016 22:10:12 +0000 (UTC) > > owl <owl@rooftop.invalid> wrote: > > > >> Melzzzzz <mel@zzzzz.com> wrote: > >> > On Wed, 20 Apr 2016 23:51:39 +0200 > >> > Peter Köhlmann <peter-koehlmann@t-online.de> wrote: > >> > > >> >> Melzzzzz wrote: > >> >> > >> >> > On Wed, 20 Apr 2016 21:41:51 +0000 (UTC) > >> >> > owl <owl@rooftop.invalid> wrote: > >> >> > > >> >> >> Melzzzzz <mel@zzzzz.com> wrote: > >> >> >> > On Wed, 20 Apr 2016 21:13:16 +0000 (UTC) > >> >> >> > owl <owl@rooftop.invalid> wrote: > >> >> >> > > >> >> >> >> Melzzzzz <mel@zzzzz.com> wrote: > >> >> >> >> > On Wed, 20 Apr 2016 17:34:37 +0000 (UTC) > >> >> >> >> > owl <owl@rooftop.invalid> wrote: > >> >> >> >> > > >> >> >> >> >> > >> >> >> >> >> I'm simultaneously running an attack on a particular > >> >> >> >> >> hash over the entire address space (those eight small > >> >> >> >> >> windows in the vid). > >> >> >> >> > > >> >> >> >> > https://eprint.iacr.org/2006/105 > >> >> >> >> > Tunnels in Hash Functions: MD5 Collisions Within a > >> >> >> >> > Minute > >> >> >> >> > >> >> >> >> Unless I'm misunderstanding things, that's just generating > >> >> >> >> collision pairs. Correct me if I'm wrong, but I assume > >> >> >> >> that all attacks against a hash still require a > >> >> >> >> dictionary of hashes (which is what I'm generating). > >> >> >> >> > >> >> >> > > >> >> >> > If you find collision of particular length, you have > >> >> >> > probable solution... > >> >> >> > >> >> >> Length of what? > >> >> >> Can you give me a layman's executive summary of how the > >> >> >> described approach can reveal the original input given only > >> >> >> the known hash? > >> >> > > >> >> > look, this algo quickly finds out source of particular hash > >> >> > value. Got it? > >> >> > >> >> Yes. For data which has nothing at all to do with the original > >> >> data. Which makes it sort of pointless > >> > > >> > If length is known there is finite number of combinations. I > >> > really doubt you can get two different ip addresses for same md5 > >> > hash... > >> > >> Which means that to derive an IP address knowing only its hash, it > >> becomes necessary to generate hashes for all possible IP addresses > >> for comparison with the given hash, right? > >> > > > > No, search for collisions of particular length. I didn't look up > > program but it is only useful with known source length, so I guess > > if you can limit solution on this algorihtm you can quickly find > > you ip address. > > > > Isn't that a contradiction of what you just said? "I really doubt > that you can get two different ip addresses for the same md5 hash". No it means when you find one collision you found solution... This algo is good for cracking md5 hashed passwords, it's good for your problem as well... >
[toc] | [prev] | [next] | [standalone]
| From | owl <owl@rooftop.invalid> |
|---|---|
| Date | 2016-04-21 00:07 +0000 |
| Message-ID | <fhgjdk903.af@rooftop.invalid> |
| In reply to | #351083 |
Melzzzzz <mel@zzzzz.com> wrote: > On Wed, 20 Apr 2016 22:19:04 +0000 (UTC) > owl <owl@rooftop.invalid> wrote: > >> Melzzzzz <mel@zzzzz.com> wrote: >> > On Wed, 20 Apr 2016 22:10:12 +0000 (UTC) >> > owl <owl@rooftop.invalid> wrote: >> > >> >> Melzzzzz <mel@zzzzz.com> wrote: >> >> > On Wed, 20 Apr 2016 23:51:39 +0200 >> >> > Peter Köhlmann <peter-koehlmann@t-online.de> wrote: >> >> > >> >> >> Melzzzzz wrote: >> >> >> >> >> >> > On Wed, 20 Apr 2016 21:41:51 +0000 (UTC) >> >> >> > owl <owl@rooftop.invalid> wrote: >> >> >> > >> >> >> >> Melzzzzz <mel@zzzzz.com> wrote: >> >> >> >> > On Wed, 20 Apr 2016 21:13:16 +0000 (UTC) >> >> >> >> > owl <owl@rooftop.invalid> wrote: >> >> >> >> > >> >> >> >> >> Melzzzzz <mel@zzzzz.com> wrote: >> >> >> >> >> > On Wed, 20 Apr 2016 17:34:37 +0000 (UTC) >> >> >> >> >> > owl <owl@rooftop.invalid> wrote: >> >> >> >> >> > >> >> >> >> >> >> >> >> >> >> >> >> I'm simultaneously running an attack on a particular >> >> >> >> >> >> hash over the entire address space (those eight small >> >> >> >> >> >> windows in the vid). >> >> >> >> >> > >> >> >> >> >> > https://eprint.iacr.org/2006/105 >> >> >> >> >> > Tunnels in Hash Functions: MD5 Collisions Within a >> >> >> >> >> > Minute >> >> >> >> >> >> >> >> >> >> Unless I'm misunderstanding things, that's just generating >> >> >> >> >> collision pairs. Correct me if I'm wrong, but I assume >> >> >> >> >> that all attacks against a hash still require a >> >> >> >> >> dictionary of hashes (which is what I'm generating). >> >> >> >> >> >> >> >> >> > >> >> >> >> > If you find collision of particular length, you have >> >> >> >> > probable solution... >> >> >> >> >> >> >> >> Length of what? >> >> >> >> Can you give me a layman's executive summary of how the >> >> >> >> described approach can reveal the original input given only >> >> >> >> the known hash? >> >> >> > >> >> >> > look, this algo quickly finds out source of particular hash >> >> >> > value. Got it? >> >> >> >> >> >> Yes. For data which has nothing at all to do with the original >> >> >> data. Which makes it sort of pointless >> >> > >> >> > If length is known there is finite number of combinations. I >> >> > really doubt you can get two different ip addresses for same md5 >> >> > hash... >> >> >> >> Which means that to derive an IP address knowing only its hash, it >> >> becomes necessary to generate hashes for all possible IP addresses >> >> for comparison with the given hash, right? >> >> >> > >> > No, search for collisions of particular length. I didn't look up >> > program but it is only useful with known source length, so I guess >> > if you can limit solution on this algorihtm you can quickly find >> > you ip address. >> > >> >> Isn't that a contradiction of what you just said? "I really doubt >> that you can get two different ip addresses for the same md5 hash". > > No it means when you find one collision you found solution... A collision with what? > This algo is good for cracking md5 hashed passwords, it's good for your > problem as well... >> > How does it do that without a dictionary? I still don't understand how a collision helps. IOW, even if "blah" and "foo" both collide producing the same hash, how does knowing only the hash tell me anything?
[toc] | [prev] | [next] | [standalone]
| From | DFS <nospam@dfs.com> |
|---|---|
| Date | 2016-04-20 23:17 -0400 |
| Message-ID | <nf9gib$6c1$2@dont-email.me> |
| In reply to | #351022 |
On 4/20/2016 1:34 PM, owl wrote: > So, I am creating an md5 lookup table for all IPv4 addresses. > That will take several months to create what will be about > 200GB file in the format I'm using: Hardcore stalking /freak/!
[toc] | [prev] | [next] | [standalone]
| From | owl <owl@rooftop.invalid> |
|---|---|
| Date | 2016-04-21 03:49 +0000 |
| Message-ID | <tuo0aa.fko@rooftop.invalid> |
| In reply to | #351110 |
DFS <nospam@dfs.com> wrote: > On 4/20/2016 1:34 PM, owl wrote: > > >> So, I am creating an md5 lookup table for all IPv4 addresses. >> That will take several months to create what will be about >> 200GB file in the format I'm using: > > > Hardcore stalking /freak/! > Don't worry. I'm not going to post yours or flatfish+++ even if it gets a match. The thing's tying up my computer so much I doubt I'll even let it finish. If I had another machine with a big enough drive I'd set it to work and not care, but this is a laptop and I'm using an iffy WD USB drive to hold the file. Not sure I want to risk it. Interesting project anyway. Maybe one for the future.
[toc] | [prev] | [next] | [standalone]
| From | DFS <nospam@dfs.com> |
|---|---|
| Date | 2016-04-21 10:27 -0400 |
| Message-ID | <nfanpl$2hl$1@dont-email.me> |
| In reply to | #351111 |
On 4/20/2016 11:49 PM, owl wrote: > DFS <nospam@dfs.com> wrote: >> On 4/20/2016 1:34 PM, owl wrote: >> >> >>> So, I am creating an md5 lookup table for all IPv4 addresses. >>> That will take several months to create what will be about >>> 200GB file in the format I'm using: >> >> >> Hardcore stalking /freak/! >> > > Don't worry. I'm not going to post yours or flatfish+++ even > if it gets a match. The thing's tying up my computer so much > I doubt I'll even let it finish. If I had another machine > with a big enough drive I'd set it to work and not care, but > this is a laptop and I'm using an iffy WD USB drive to hold > the file. Not sure I want to risk it. Interesting project > anyway. Maybe one for the future. Here's the posting-host from the injection info in one of my eternal-sep posts: 5399b1c4ae39fc7dd2f40cbc5f70036e What IP does your code generate from it?
[toc] | [prev] | [next] | [standalone]
| From | owl <owl@rooftop.invalid> |
|---|---|
| Date | 2016-04-21 16:26 +0000 |
| Message-ID | <ghjd00aa.arf@rooftop.invalid> |
| In reply to | #351140 |
DFS <nospam@dfs.com> wrote: > On 4/20/2016 11:49 PM, owl wrote: >> DFS <nospam@dfs.com> wrote: >>> On 4/20/2016 1:34 PM, owl wrote: >>> >>> >>>> So, I am creating an md5 lookup table for all IPv4 addresses. >>>> That will take several months to create what will be about >>>> 200GB file in the format I'm using: >>> >>> >>> Hardcore stalking /freak/! >>> >> >> Don't worry. I'm not going to post yours or flatfish+++ even >> if it gets a match. The thing's tying up my computer so much >> I doubt I'll even let it finish. If I had another machine >> with a big enough drive I'd set it to work and not care, but >> this is a laptop and I'm using an iffy WD USB drive to hold >> the file. Not sure I want to risk it. Interesting project >> anyway. Maybe one for the future. > > > Here's the posting-host from the injection info in one of my eternal-sep > posts: 5399b1c4ae39fc7dd2f40cbc5f70036e > > What IP does your code generate from it? > It doesn't. I turned it off. It would if I let it run for ~90 days and had a map file of IP -> md5(IP) for all IPv4 addresses, assuming the original string is in exactly that form. You can tell me if it *does* represent an ip address in that form by running: echo -n "your.ip.address" | md5sum
[toc] | [prev] | [standalone]
Page 2 of 2 — ← Prev page 1 [2]
Back to top | Article view | comp.os.linux.advocacy
csiph-web