Jump to content



Welcome to AstaHost - Dear Guest , Please Register here to get Your own website. - Ask a Question / Express Opinion / Reply w/o Sign-Up!

Toggle shoutbox Shoutbox Open the Shoutbox in a popup

@  yordan : (19 June 2013 - 02:28 PM) Long Life To Asta New Era
@  agyat : (19 June 2013 - 01:58 PM) New Era Start At Asta Or Asta Start In New Era. :unsure:
@  yordan : (16 June 2013 - 05:41 PM) You're Welcome, Agyat!
@  agyat : (16 June 2013 - 07:38 AM) Thanks Yordan...
@  velma : (16 June 2013 - 12:06 AM) I Have Asked Opa To Check For A Backup.. He'll Let Me Know Soon :)
@  velma : (16 June 2013 - 12:05 AM) T_T It Seems That Someone Has Deleted That Topic Since I Found The Url Of The Topic But It Gives Me An Error
@  yordan : (15 June 2013 - 10:31 PM) @velma : It's A Tuto On How To Create A Login Program.
@  yordan : (15 June 2013 - 10:31 PM) Happy Birthday To Youuuuuu Agyat!
@  yordan : (15 June 2013 - 10:31 PM) Ba$
@  agyat : (15 June 2013 - 04:41 PM) :(
@  agyat : (15 June 2013 - 04:41 PM) Where The Hall I Were? 15Th Is Almost At End And No-One Wished Me "happy Birthday"!!!
@  velma : (14 June 2013 - 10:39 AM) Which Tutorial Is He Searching For?
@  velma : (14 June 2013 - 10:38 AM) Which Tutorial Is He Searching For?
@  yordan : (14 June 2013 - 07:47 AM) Ok, Have A Look Tomorrow.
@  yordan : (13 June 2013 - 03:19 PM) @velma, Can You Have A Look At Feelay's Problem? Seems That His Tutorial Is Not Searchable Today.
@  Feelay : (13 June 2013 - 08:11 AM) Oh, Haha
@  velma : (12 June 2013 - 05:39 PM) T_T Lately My Levels Of Procrastination..... **sigh**
@  velma : (12 June 2013 - 05:38 PM) I'll Do It Later
@  velma : (12 June 2013 - 05:38 PM) Procrastinators.. People Who Keep Saying "i'll Do This In A Bit"
@  Feelay : (12 June 2013 - 02:05 PM) Deal Punishments To What?

Photo
- - - - -

Md5 Rainbow Tables


10 replies to this topic

#1 tansqrx

tansqrx

    Super Member

  • [HOSTED]
  • 759 posts

Posted 27 April 2005 - 09:09 PM

I have recently been playing around with rainbow tables. If you don't know what they are then look at www.antsight.com/zsl/rainbowcrack/ They are basically a precomplied hash table of all possible values from a particular algorithm. The most common are for the Windows Lanman hashes which can crack any possible Windows SAM in little to no time. My question is are there similar tables circulating for MD5? I got the Windows tables from bit torrent which were around 12 Gb compressed and 64 uncompressed.

#2 marijnnn

marijnnn

    Premium Member

  • [HOSTED]
  • 336 posts

Posted 28 April 2005 - 06:34 PM

yep, the idea is the same. they don't actuall crack it. they just try out any string and take the hash of it. it's ok if you know that the word you are looking for is about 8 letters long, a password or so, but it might as well be something completely different. besides, if you hash it twice, no way they'll find it...

it's kinda stupid i think.

#3 tansqrx

tansqrx

    Super Member

  • [HOSTED]
  • 759 posts

Posted 28 April 2005 - 07:58 PM

Stupid? No way, there are still plenty of applications out there that use a MD5 hash and a plain MD5 hash at that. I agree, hashing twice or adding a seed value will throw off the rainbow tables, but as I said there are still plenty of apps that this would be useful against.

#4 SubTen

SubTen

    Newbie [ Level 1 ]

  • Members
  • 1 posts

Posted 27 May 2005 - 09:55 PM

But hashing twice won't necessarily do anything security-wise. Since a hash can have multiple corresponding passwords any password that creates the same hash is a correct password. Hashing twice only keeps someone from getting the original password.

#5 Guest_FeedBacker_*

Guest_FeedBacker_*
  • Guests

Posted 26 February 2008 - 12:10 AM

Replying to SubTen
No, actually, even if you hash it twice, you can still crack it pretty easily with rainbowtables.

#6 naro2212

naro2212

    Newbie [ Level 2 ]

  • Members
  • 12 posts

Posted 17 March 2008 - 11:22 PM

yea you can hack it easly wiht rainbow tabs in my opion we should develept finger print scaners as passwords

#7 docduke

docduke

    Advanced Member

  • Members
  • 152 posts

Posted 19 March 2008 - 01:39 AM

There is a Live CD version of Rainbow Tables, called OPHcrack. It is discussed in DistroWatch, which is where I first heard of it. It is imbedded in a copy of Slackware Linux.

I tried it on Windows XP, on a system which had 4 user accounts. It cracked only one of them, which had an all-uppercase 8-character alphabetic password.

This is neither a testimonial nor a complaint. I had never before heard of Rainbow Tables, and was curious what they could do. If you wish to try them out, a Live CD is certainly a simple way to do it. In praise of OPHcrack, I booted it on a computer that has 4 hard drives. It correctly identified the 4 Windows partitions, and let me tell it which one to attack.

#8 tansqrx

tansqrx

    Super Member

  • [HOSTED]
  • 759 posts

Posted 01 April 2008 - 05:27 PM

yea you can hack it easly wiht rainbow tabs in my opion we should develept finger print scaners as passwords


It’s funny that you mention using your fingerprints as passwords. Today I read an article where hackers have basically made a fingerprint keylogger. http://www.darkreadi...p?doc_id=149661

If you think biometric scans are necessarily secure, think again: A European researcher has built a biometric keylogger that can capture fingerprint or other scans.



#9 Guest_(G)YH_*

Guest_(G)YH_*
  • Guests

Posted 14 March 2009 - 05:12 PM

questionMd5 Rainbow Tables

is there a site which can convert LN hashes to text online?

Please reply



#10 Atomic0

Atomic0

    Premium Member

  • [HOSTED]
  • 390 posts
  • Gender:Male
  • myCENTs:92.30

Posted 29 May 2009 - 12:44 PM

You might want to try the database hosted at: http://hash.insidepro.com/

If you can't find your password / hash set in the database, you may want to try posting at: http://forum.insidep...m/index.php?c=3
to get some password recovery assistance for free.

#11 Guest_(G)Graham_*

Guest_(G)Graham_*
  • Guests

Posted 07 March 2011 - 08:51 PM

md5*2 wont save youMd5 Rainbow Tables

say someone breaks into your database and steals all the passwords but you passwords are md5(md5($password)); well the already have the outcome of that from getting the password now if they have a big enough rainbow db they can just look up the hash they have it will give them the second hash then they look that up and they have the password if you really want to keep your stuff safe use 2 different types of cryptology and a salt

-reply by Graham



Reply to this topic



  


0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users