|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 62
Members: 0
Total: 62
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
Un-Salt Salted Hashes? |
|
Posted: Sat Jul 30, 2005 3:33 pm |
|
|
Matt |
Regular user |
|
|
Joined: Jul 30, 2005 |
Posts: 7 |
|
|
|
|
|
|
|
okay, seeing as this is my first post here i feel i should introduce myself.
im matt, 16yrs old. just started programing in vb about 3 months ago. don't really know much, execpt for simple operations like webbrowsers and calculations. i've been browsing through waraxe for a while now learning new stuff, and i finally deicided to post.
okay, now to my theory;
since there is a formula for salted hashes - MD5( MD5( password + salt ) + password )
i figure that there must be a way to reverse it, for example take the forumla and do the oppisite operations - (((salt - pass) - pass) / md5) / md5
im not sure if that's correct or not, or if its even posiable.
is there a known way to unsalt a salted hash if you know the salted hash and the salt?
i heard c++ has the ability to unsalt hashes.
well, thanks for your time |
|
|
|
|
|
|
|
|
Posted: Thu May 22, 2008 8:45 am |
|
|
lenny |
Valuable expert |
|
|
Joined: May 15, 2008 |
Posts: 275 |
|
|
|
|
|
|
|
Well it is kind of possible. In order to take the pass from the salt, you would need to know both the length of the initial password and the length of the salt.
Anyway, let me get this streight: You take and MD5, find the MD5 of the salt and subtract that algorithmically from the hash. You use the remainder to.... no hang on - thats not possible. I like the reasoning, but it seems pretty impossible due to the way in which hashes always produce equal length outputs!
Anybody else have any comments? |
|
|
|
|
Posted: Thu May 22, 2008 7:23 pm |
|
|
Unic0rn |
Regular user |
|
|
Joined: May 02, 2008 |
Posts: 10 |
|
|
|
|
|
|
|
Cant be done. MD5 is one-way only. |
|
|
|
|
Posted: Thu May 22, 2008 7:54 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
Yes, 100% true - any kind of "unsalting" is not possible. Period. |
|
|
|
|
www.waraxe.us Forum Index -> Hash related information
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|