Go Back   vb.org Archive > vBulletin 3 Discussion > vB3 General Discussions
FAQ Community Calendar Today's Posts Search

Closed Thread
 
Thread Tools Display Modes
  #1  
Old 01-30-2007, 12:27 AM
Snake's Avatar
Snake Snake is offline
 
Join Date: Mar 2005
Location: Cleveland, OH
Posts: 3,832
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default Cracking the MD5 passwords?

Alright I'm tired of this bullshit. I really need to find a way to crack up the MD5 passwords of a user in the database because my forums keep getting hacked over and over again and I have a way to prevent this from happening in the future. I don't care what it's gonna cost me as long as I can find out the passwords.

So any help is greatly appreciated!
  #2  
Old 01-30-2007, 12:36 AM
V3RT1G0 V3RT1G0 is offline
 
Join Date: Apr 2006
Posts: 12
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

you cant crack em... they are salted so basically impossible... even those bruters cant figure out the hashes but you can be getting hacked by them hijacking a cookie of yours and then using that salted hashed that is still encrypted to log in...

just a thought
  #3  
Old 01-30-2007, 12:39 AM
Snake's Avatar
Snake Snake is offline
 
Join Date: Mar 2005
Location: Cleveland, OH
Posts: 3,832
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Of course I can crack them. Everything is possible in vBulletin, if you ask me. But only if Jelsoft would be nice enough to tell me on how to do that.
  #4  
Old 01-30-2007, 01:08 AM
V3RT1G0 V3RT1G0 is offline
 
Join Date: Apr 2006
Posts: 12
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Snake View Post
Of course I can crack them. Everything is possible in vBulletin, if you ask me. But only if Jelsoft would be nice enough to tell me on how to do that.
well wouldnt that just ruin the whole security experience? lol
  #5  
Old 01-30-2007, 01:14 AM
Snake's Avatar
Snake Snake is offline
 
Join Date: Mar 2005
Location: Cleveland, OH
Posts: 3,832
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by V3RT1G0 View Post
well wouldnt that just ruin the whole security experience? lol
Well wouldn't you rather be safe about the whole thing as well?
  #6  
Old 01-30-2007, 01:16 AM
V3RT1G0 V3RT1G0 is offline
 
Join Date: Apr 2006
Posts: 12
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Snake View Post
Well wouldn't you rather be safe about the whole thing as well?
well prolly but im sure thats all they can do... i mean salted hashes is the highest security you can get with passwords... its hella better than IPBs salted hashes
  #7  
Old 01-30-2007, 01:21 AM
Adrian Schneider's Avatar
Adrian Schneider Adrian Schneider is offline
 
Join Date: Jul 2004
Posts: 2,528
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

I don't understand your logic...

You want to prevent hacking by cracking your passwords? Doesn't make sense to me.

Anyway... an md5 hash is a 32char unique (not 100% unique, but close) string using hex numbers. Hashes are one way, so you can't "crack" them, but you can try to find other strings which give you the same hash result (aka a collision). Since the passwords as hashed twice like this:

md5(md5(password) . salt)

it will take a LOT of CPU power to try and find the original password. You'd first to first get all the 32 + salt (3?) character strings that give you the final hash, and then of all of those, you'd have to find all the possible strings that give you the first 32 characters of it.



I think it's safe to say the password storing method is NOT the problem here.
  #8  
Old 01-30-2007, 01:30 AM
Snake's Avatar
Snake Snake is offline
 
Join Date: Mar 2005
Location: Cleveland, OH
Posts: 3,832
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

You don't understand why I'm doing this, SirAdrian. I have a few members who are well known as hackers on my forums so I'm thinking of cracking up their passwords on my forums and see if they work on THEIR forum so I can gain access to their ACP and their stupid ass hidden forum which has all the info of hacking vBulletin sites. I wish if vB.com/Jelsoft could do something about that vB site since it's all related to porn and hacking which I doubt that they will take any action. And since Jelsoft won't be able to do this and no one is able to stop them, why can't I do that instead? You don't realize how many Final Fantasy forums they have hacked lately and you don't even know a thing or two about them. Seeing as my FF forum is doing great, I believe I am their next target now. I've been hacked for once already but no, not this time sorry.

I am going through a lot of stress and pain here just so I could find the hashed passwords. I hope someone will be able to help me out here.

Quote:
Originally Posted by SirAdrian
it will take a LOT of CPU power to try and find the original password. You'd first to first get all the 32 + salt (3?) character strings that give you the final hash, and then of all of those, you'd have to find all the possible strings that give you the first 32 characters of it.
Oh that's all I gotta do? Well, it looks simple to me. I mean, I can always hire a professional coder to do that for me. And I'm sure someone in here might be able to do that.
  #9  
Old 01-30-2007, 01:43 AM
Jorrit787 Jorrit787 is offline
 
Join Date: Nov 2005
Location: The Netherlands
Posts: 63
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Snake View Post
You don't understand why I'm doing this, SirAdrian. I have a few members who are well known as hackers on my forums so I'm thinking of cracking up their passwords on my forums and see if they work on THEIR forum so I can gain access to their ACP and their stupid ass hidden forum which has all the info of hacking vBulletin sites.
However "noble" your intentions may be, I do believe you can get into trouble with the law for doing this.
  #10  
Old 01-30-2007, 02:28 AM
Snake's Avatar
Snake Snake is offline
 
Join Date: Mar 2005
Location: Cleveland, OH
Posts: 3,832
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

So I will be getting into trouble and not them since they are the ones who go around forums and hack them up? That's pathetic!
Closed Thread


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 03:24 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.04423 seconds
  • Memory Usage 2,248KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (5)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (2)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete