corigin.com

sofware news

Using Google to Crack Hashed Passwords

Posted in  (November 26, 2007 at 1:07 am)

Clever:

…I thought it would be interesting to find out the account password. Wordpress stores raw MD5 hashes in the user database…. As with any respectable hash function, it is believed to be computationally infeasible to discover the input of MD5 from an output. Instead, someone would have to try out all possible inputs until the correct output is discovered.

[…]

Instead, I asked Google. I found, for example, a genealogy page listing people with the surname “Anthony”, and an advert for a house, signing off “Please Call for showing. Thank you, Anthony”. And indeed, the MD5 hash of “Anthony” was the database entry for the attacker. I had discovered his password.

…more

New Identity Theft ToolLessons from the Ft. Dix Terrorist PlottersDemos Report on National SecurityDual_EC_DRBG Added to Windows VistaHandbook of Applied Cryptography Online

Leave a Reply

You must be logged in to post a comment.