Nov 21, 2009

Md5 Rainbow Tables

free web hosting
Open Discussion & Free Web Hosting > Computers & Tech > Security issues & Exploits

Md5 Rainbow Tables

tansqrx
I have recently been playing around with rainbow tables. If you don't know what they are then look at www.antsight.com/zsl/rainbowcrack/ They are basically a precomplied hash table of all possible values from a particular algorithm. The most common are for the Windows Lanman hashes which can crack any possible Windows SAM in little to no time. My question is are there similar tables circulating for MD5? I got the Windows tables from bit torrent which were around 12 Gb compressed and 64 uncompressed.

Comment/Reply (w/o sign-up)

marijnnn
yep, the idea is the same. they don't actuall crack it. they just try out any string and take the hash of it. it's ok if you know that the word you are looking for is about 8 letters long, a password or so, but it might as well be something completely different. besides, if you hash it twice, no way they'll find it...

it's kinda stupid i think.

Comment/Reply (w/o sign-up)

tansqrx
Stupid? No way, there are still plenty of applications out there that use a MD5 hash and a plain MD5 hash at that. I agree, hashing twice or adding a seed value will throw off the rainbow tables, but as I said there are still plenty of apps that this would be useful against.

Comment/Reply (w/o sign-up)

SubTen
But hashing twice won't necessarily do anything security-wise. Since a hash can have multiple corresponding passwords any password that creates the same hash is a correct password. Hashing twice only keeps someone from getting the original password.

Comment/Reply (w/o sign-up)

FeedBacker
Replying to SubTen
No, actually, even if you hash it twice, you can still crack it pretty easily with rainbowtables.

Comment/Reply (w/o sign-up)

naro2212
yea you can hack it easly wiht rainbow tabs in my opion we should develept finger print scaners as passwords

Comment/Reply (w/o sign-up)

docduke
There is a Live CD version of Rainbow Tables, called OPHcrack. It is discussed in DistroWatch, which is where I first heard of it. It is imbedded in a copy of Slackware Linux.

I tried it on Windows XP, on a system which had 4 user accounts. It cracked only one of them, which had an all-uppercase 8-character alphabetic password.

This is neither a testimonial nor a complaint. I had never before heard of Rainbow Tables, and was curious what they could do. If you wish to try them out, a Live CD is certainly a simple way to do it. In praise of OPHcrack, I booted it on a computer that has 4 hard drives. It correctly identified the 4 Windows partitions, and let me tell it which one to attack.

Comment/Reply (w/o sign-up)

tansqrx
QUOTE(naro2212 @ Mar 17 2008, 06:22 PM) *
yea you can hack it easly wiht rainbow tabs in my opion we should develept finger print scaners as passwords


It’s funny that you mention using your fingerprints as passwords. Today I read an article where hackers have basically made a fingerprint keylogger. http://www.darkreading.com/document.asp?doc_id=149661

QUOTE
If you think biometric scans are necessarily secure, think again: A European researcher has built a biometric keylogger that can capture fingerprint or other scans.

Comment/Reply (w/o sign-up)

(G)YH
question
Md5 Rainbow Tables

is there a site which can convert LN hashes to text online?

Please reply


Comment/Reply (w/o sign-up)

Atomic0
You might want to try the database hosted at: http://hash.insidepro.com/

If you can't find your password / hash set in the database, you may want to try posting at: http://forum.insidepro.com/index.php?c=3
to get some password recovery assistance for free.

Comment/Reply (w/o sign-up)


Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

This textarea will convert to Rich-Text automatically (IE, Firefox, Chrome)

Similar Topics

Keywords : Md5 Rainbow Tables


    Looking for md5, rainbow, tables

See Also,

*SIMILAR VIDEOS*
Searching Video's for md5, rainbow, tables
advertisement



Md5 Rainbow Tables

Affordable Web Hosting, Low cost Web Hosting - ComputingHost.com