vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   Cracking the MD5 passwords? (https://vborg.vbsupport.ru/showthread.php?t=137897)

Snake 01-30-2007 12:27 AM

Cracking the MD5 passwords?
 
Alright I'm tired of this bullshit. I really need to find a way to crack up the MD5 passwords of a user in the database because my forums keep getting hacked over and over again and I have a way to prevent this from happening in the future. I don't care what it's gonna cost me as long as I can find out the passwords.

So any help is greatly appreciated!

V3RT1G0 01-30-2007 12:36 AM

you cant crack em... they are salted so basically impossible... even those bruters cant figure out the hashes but you can be getting hacked by them hijacking a cookie of yours and then using that salted hashed that is still encrypted to log in...

just a thought :)

Snake 01-30-2007 12:39 AM

Of course I can crack them. Everything is possible in vBulletin, if you ask me. But only if Jelsoft would be nice enough to tell me on how to do that.

V3RT1G0 01-30-2007 01:08 AM

Quote:

Originally Posted by Snake (Post 1170213)
Of course I can crack them. Everything is possible in vBulletin, if you ask me. But only if Jelsoft would be nice enough to tell me on how to do that.

well wouldnt that just ruin the whole security experience? lol

Snake 01-30-2007 01:14 AM

Quote:

Originally Posted by V3RT1G0 (Post 1170227)
well wouldnt that just ruin the whole security experience? lol

Well wouldn't you rather be safe about the whole thing as well?

V3RT1G0 01-30-2007 01:16 AM

Quote:

Originally Posted by Snake (Post 1170233)
Well wouldn't you rather be safe about the whole thing as well?

well prolly but im sure thats all they can do... i mean salted hashes is the highest security you can get with passwords... its hella better than IPBs salted hashes

Adrian Schneider 01-30-2007 01:21 AM

I don't understand your logic...

You want to prevent hacking by cracking your passwords? Doesn't make sense to me. :)

Anyway... an md5 hash is a 32char unique (not 100% unique, but close) string using hex numbers. Hashes are one way, so you can't "crack" them, but you can try to find other strings which give you the same hash result (aka a collision). Since the passwords as hashed twice like this:

md5(md5(password) . salt)

it will take a LOT of CPU power to try and find the original password. You'd first to first get all the 32 + salt (3?) character strings that give you the final hash, and then of all of those, you'd have to find all the possible strings that give you the first 32 characters of it.



I think it's safe to say the password storing method is NOT the problem here.

Snake 01-30-2007 01:30 AM

You don't understand why I'm doing this, SirAdrian. I have a few members who are well known as hackers on my forums so I'm thinking of cracking up their passwords on my forums and see if they work on THEIR forum so I can gain access to their ACP and their stupid ass hidden forum which has all the info of hacking vBulletin sites. I wish if vB.com/Jelsoft could do something about that vB site since it's all related to porn and hacking which I doubt that they will take any action. And since Jelsoft won't be able to do this and no one is able to stop them, why can't I do that instead? You don't realize how many Final Fantasy forums they have hacked lately and you don't even know a thing or two about them. Seeing as my FF forum is doing great, I believe I am their next target now. I've been hacked for once already but no, not this time sorry.

I am going through a lot of stress and pain here just so I could find the hashed passwords. I hope someone will be able to help me out here.

Quote:

Originally Posted by SirAdrian
it will take a LOT of CPU power to try and find the original password. You'd first to first get all the 32 + salt (3?) character strings that give you the final hash, and then of all of those, you'd have to find all the possible strings that give you the first 32 characters of it.

Oh that's all I gotta do? Well, it looks simple to me. I mean, I can always hire a professional coder to do that for me. And I'm sure someone in here might be able to do that.

Jorrit787 01-30-2007 01:43 AM

Quote:

Originally Posted by Snake (Post 1170243)
You don't understand why I'm doing this, SirAdrian. I have a few members who are well known as hackers on my forums so I'm thinking of cracking up their passwords on my forums and see if they work on THEIR forum so I can gain access to their ACP and their stupid ass hidden forum which has all the info of hacking vBulletin sites.

However "noble" your intentions may be, I do believe you can get into trouble with the law for doing this.

Snake 01-30-2007 02:28 AM

So I will be getting into trouble and not them since they are the ones who go around forums and hack them up? That's pathetic!


All times are GMT. The time now is 01:00 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01408 seconds
  • Memory Usage 1,737KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (5)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (10)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • pagenav_page
  • pagenav_complete
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete