Welcome Guest ( Log In | Register )



 
Reply to this topicStart new topic
> Md5 Rainbow Tables
tansqrx
post Apr 27 2005, 09:09 PM
Post #1


Super Member
Group Icon

Group: [HOSTED]
Posts: 508
Joined: 25-April 05
Member No.: 4,374



I have recently been playing around with rainbow tables. If you don't know what they are then look at www.antsight.com/zsl/rainbowcrack/ They are basically a precomplied hash table of all possible values from a particular algorithm. The most common are for the Windows Lanman hashes which can crack any possible Windows SAM in little to no time. My question is are there similar tables circulating for MD5? I got the Windows tables from bit torrent which were around 12 Gb compressed and 64 uncompressed.
Go to the top of the page
 
+Quote Post
marijnnn
post Apr 28 2005, 06:34 PM
Post #2


Premium Member
Group Icon

Group: [HOSTED]
Posts: 336
Joined: 22-September 04
Member No.: 798



yep, the idea is the same. they don't actuall crack it. they just try out any string and take the hash of it. it's ok if you know that the word you are looking for is about 8 letters long, a password or so, but it might as well be something completely different. besides, if you hash it twice, no way they'll find it...

it's kinda stupid i think.
Go to the top of the page
 
+Quote Post
tansqrx
post Apr 28 2005, 07:58 PM
Post #3


Super Member
Group Icon

Group: [HOSTED]
Posts: 508
Joined: 25-April 05
Member No.: 4,374



Stupid? No way, there are still plenty of applications out there that use a MD5 hash and a plain MD5 hash at that. I agree, hashing twice or adding a seed value will throw off the rainbow tables, but as I said there are still plenty of apps that this would be useful against.
Go to the top of the page
 
+Quote Post
SubTen
post May 27 2005, 09:55 PM
Post #4


Newbie [ Level 1 ]
Group Icon

Group: Members
Posts: 1
Joined: 27-May 05
Member No.: 5,517



But hashing twice won't necessarily do anything security-wise. Since a hash can have multiple corresponding passwords any password that creates the same hash is a correct password. Hashing twice only keeps someone from getting the original password.
Go to the top of the page
 
+Quote Post
iGuest
post Feb 26 2008, 12:10 AM
Post #5


Newbie [ Level 1 ]
Group Icon

Group: Members
Posts: 0
Joined: 1-November 07
Member No.: 25,869



Replying to SubTen
No, actually, even if you hash it twice, you can still crack it pretty easily with rainbowtables.
Go to the top of the page
 
+Quote Post
naro2212
post Mar 17 2008, 11:22 PM
Post #6


Newbie [ Level 2 ]
Group Icon

Group: Members
Posts: 12
Joined: 17-March 08
Member No.: 29,182



yea you can hack it easly wiht rainbow tabs in my opion we should develept finger print scaners as passwords
Go to the top of the page
 
+Quote Post
docduke
post Mar 19 2008, 01:39 AM
Post #7


Advanced Member
Group Icon

Group: [MODERATOR]
Posts: 102
Joined: 8-January 08
Member No.: 27,477



There is a Live CD version of Rainbow Tables, called OPHcrack. It is discussed in DistroWatch, which is where I first heard of it. It is imbedded in a copy of Slackware Linux.

I tried it on Windows XP, on a system which had 4 user accounts. It cracked only one of them, which had an all-uppercase 8-character alphabetic password.

This is neither a testimonial nor a complaint. I had never before heard of Rainbow Tables, and was curious what they could do. If you wish to try them out, a Live CD is certainly a simple way to do it. In praise of OPHcrack, I booted it on a computer that has 4 hard drives. It correctly identified the 4 Windows partitions, and let me tell it which one to attack.
Go to the top of the page
 
+Quote Post
tansqrx
post Apr 1 2008, 05:27 PM
Post #8


Super Member
Group Icon

Group: [HOSTED]
Posts: 508
Joined: 25-April 05
Member No.: 4,374



QUOTE(naro2212 @ Mar 17 2008, 06:22 PM) *
yea you can hack it easly wiht rainbow tabs in my opion we should develept finger print scaners as passwords


It’s funny that you mention using your fingerprints as passwords. Today I read an article where hackers have basically made a fingerprint keylogger. http://www.darkreading.com/document.asp?doc_id=149661

QUOTE
If you think biometric scans are necessarily secure, think again: A European researcher has built a biometric keylogger that can capture fingerprint or other scans.
Go to the top of the page
 
+Quote Post

Fast ReplyReply to this topicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. CSS for tables with diferent rows(11)
  2. Divs/ tables ?(19)
  3. Rainbow Six 3: Black Arrow And Ghost Recon 2(2)
  4. Div Tags Vs Tables For Layout(10)
  5. Rainbow 6: Lockdown(3)
  6. Help Needed: Tables(7)
  7. Table Layout Vs. Css Layout(18)
  8. Recover Tables From A MySQL .frm File(6)
  9. Access Tables(1)
  10. Let's Make Rainbow Link(1)
  11. Tables With Invision Board Is Possible!(3)
  12. Creating Tables In MySQL On Home Comp(8)
  13. Rainbow Six Lockdown Demo(1)
  14. User Priveileges Vs. Tables Vs Rows(1)
  15. Change Table Colors On Mouse Effects!(8)
  1. Database Tables Gone?(1)
  2. Updating A Database's Tables(10)
  3. MySQL, Multiple Tables(24)
  4. Linking Two Tables(12)
  5. Css Vs. Tables - A Reflection...(14)
  6. (help With Sql And Php)retrive Datas From Realted Tables And Display Them!(4)
  7. Some Odd Things With Html Tables(1)
  8. Script Tables On Sql Server Compact(0)
  9. Mysql Problem(1)


 



- Lo-Fi Version Time is now: 24th July 2008 - 08:55 PM