CyberNet News
Please login or register.

Login with username, password and session length
Pages: [1]   Go Down

Author Topic: md5 hashes not so safe after all...  (Read 2854 times)

0 Members and 1 Guest are viewing this topic.

Pieter

  • Sr. Member
  • ****
  • Reputation: 34
  • Posts: 793
    • View Profile
    • WWW
md5 hashes not so safe after all...
« on: December 14, 2007, 08:18:46 AM »
This is scary...



Many sites rely on the md5 algorithm to secure their users' passwords. Well, there's this site that allows you to decrypt md5 hashes. That's right, you can decrypt passwords with this tool! Could this be the end of md5?

To put this into perspective: this site relies on database of md5 hashes but they keep indexing random strings. Passwords with up to three characters or five numbers can be decrypted with ease. My guess is that if I were to check back in a few months, you could decrypt just about any password with up to five characters. And that's creepy. Before you know it, you can decrypt any password using their md5 decryptor...

Site: http://md5.rednoize.com/

Some random tests:
21232f297a57a5a743894a0e4a801fc3 - CRACKED (admin)
5f4dcc3b5aa765d61d8327deb882cf99 - CRACKED (password)
33c5d4954da881814420f3ba39772644 - CRACKED (crackme)
ec79d4bed810ed64267d169b0d37373e - CRACKED (8612)
61ebd641ffb9b13f2b3163677ef58b0a - CRACKED (2w9)
2eaa8683175fa19f2710707e793b1f04 - FAILED (2w9ss)
68dc6cbea6ddad512bc670c0df5c0804 - CRACKED (23984)
22604bba610abedf926b74646008896f - FAILED (613593)
031e174662676c05db4e019eaaa4de3d - FAILED (65151611)
e425adc17b1e4feed1dc295b82d16cbd - FAILED (crackme123)
80e48c2df0e639b36cf2a2a75cbd8fdb - FAILED (imahacker)
Logged
"Programming today is a race between software engineers striving to build bigger and better idiot-proof programs, and the universe trying to produce bigger and better idiots. So far, the universe is winning." - Rich Cook

xpgeek

  • Sr. Member
  • ****
  • Reputation: 19
  • Posts: 526
    • View Profile
    • WWW
Re: md5 hashes not so safe after all...
« Reply #1 on: December 14, 2007, 02:24:32 PM »
Well, for the time being, those are pretty simple passwords its managed to crack. My passwords are ALOT more complex then that.
Logged

Ryan Wagner

  • Administrator
  • Hero Member
  • *****
  • Reputation: 51
  • Posts: 3404
    • View Profile
    • WWW
Re: md5 hashes not so safe after all...
« Reply #2 on: December 14, 2007, 03:30:11 PM »
My passwords consist of upper & lowercase letters, numbers, and symbols (although a lot of sites don't accept symbols in the password). So I don't think that it will be getting mine anytime soon. But that is indeed scary because it gives hackers an even easier way to make use of databases that they hack online.
Logged

Pieter

  • Sr. Member
  • ****
  • Reputation: 34
  • Posts: 793
    • View Profile
    • WWW
Re: md5 hashes not so safe after all...
« Reply #3 on: December 15, 2007, 11:06:55 AM »
And you know what's about to happen, right? In a few years, they'll be able to crack just about any twelve-character password. We'd better work on a safer algorithm before that happens.
Logged
"Programming today is a race between software engineers striving to build bigger and better idiot-proof programs, and the universe trying to produce bigger and better idiots. So far, the universe is winning." - Rich Cook

tafkajp

  • Jr. Member
  • **
  • Reputation: 4
  • Posts: 97
    • View Profile
Re: md5 hashes not so safe after all...
« Reply #4 on: December 15, 2007, 12:31:57 PM »
Will we still be using passwords in a few years?  Fingerprint scanners, voice and facial recognition, or retina scans could be used in the future on a widespread basis in place of, or in addition to, alphanumeric passwords. 

taf
Logged

Pieter

  • Sr. Member
  • ****
  • Reputation: 34
  • Posts: 793
    • View Profile
    • WWW
Re: md5 hashes not so safe after all...
« Reply #5 on: December 15, 2007, 01:02:13 PM »
The problem with face/finger/eye recognition is that it's not always accurate. The number of false positives (i.e. don't letting you in when you should be able to do so) and false negatives (i.e. letting strangers in) is too high. By contrast: the total number of false positives and negatives that ever occurred in our current password system is 0. Ah well, there are two sides to every penny as usual.
Logged
"Programming today is a race between software engineers striving to build bigger and better idiot-proof programs, and the universe trying to produce bigger and better idiots. So far, the universe is winning." - Rich Cook

Ryan Wagner

  • Administrator
  • Hero Member
  • *****
  • Reputation: 51
  • Posts: 3404
    • View Profile
    • WWW
Re: md5 hashes not so safe after all...
« Reply #6 on: December 15, 2007, 02:04:04 PM »
I definitely don't think that face/finger/eye recognition will be becoming popular anytime soon. Especially the fingerprint one:

<a href="http://youtube.com/v/LA4Xx5Noxyo" target="_blank" class="new_win">http://youtube.com/v/LA4Xx5Noxyo</a>
Logged

sale

  • Guest
Re: md5 hashes not so safe after all...
« Reply #7 on: May 14, 2008, 07:57:40 AM »
great tool, but it is not working
Logged

Ryan Wagner

  • Administrator
  • Hero Member
  • *****
  • Reputation: 51
  • Posts: 3404
    • View Profile
    • WWW
Re: md5 hashes not so safe after all...
« Reply #8 on: May 14, 2008, 02:59:12 PM »
great tool, but it is not working
It won't work for every hash, but still appears to be up and running.
Logged
Pages: [1]   Go Up
« previous next »