Waraxe IT Security Portal
Login or Register
December 18, 2024
Menu
Home
Logout
Discussions
Forums
Members List
IRC chat
Tools
Base64 coder
MD5 hash
CRC32 checksum
ROT13 coder
SHA-1 hash
URL-decoder
Sql Char Encoder
Affiliates
y3dips ITsec
Md5 Cracker
User Manuals
AlbumNow
Content
Content
Sections
FAQ
Top
Info
Feedback
Recommend Us
Search
Journal
Your Account
User Info
Welcome, Anonymous
Nickname
Password
(Register)

Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144

People Online:
Visitors: 100
Members: 0
Total: 100
Full disclosure
[KIS-2024-07] GFI Kerio Control <= 9.4.5 Multiple HTTP Response Splitting Vulnerabilities
RansomLordNG - anti-ransomware exploit tool
APPLE-SA-12-11-2024-9 Safari 18.2
APPLE-SA-12-11-2024-8 visionOS 2.2
APPLE-SA-12-11-2024-7 tvOS 18.2
APPLE-SA-12-11-2024-6 watchOS 11.2
APPLE-SA-12-11-2024-5 macOS Ventura 13.7.2
APPLE-SA-12-11-2024-4 macOS Sonoma 14.7.2
APPLE-SA-12-11-2024-3 macOS Sequoia 15.2
APPLE-SA-12-11-2024-2 iPadOS 17.7.3
APPLE-SA-12-11-2024-1 iOS 18.2 and iPadOS 18.2
SEC Consult SA-20241211-0 :: Reflected Cross-Site Scripting in Numerix License Server Administration System Login
St. Poelten UAS | Multiple Vulnerabilities in ORing IAP
SEC Consult SA-20241204-0 :: Multiple Critical Vulnerabilities in Image Access Scan2Net (14 CVE)
Microsoft Warbird and PMP security research - technical doc
Log in Register Forum FAQ Memberlist Search
IT Security and Insecurity Portal

www.waraxe.us Forum Index -> General discussion -> Cracking a zip file
Post new topicReply to topic View previous topic :: View next topic
Cracking a zip file
PostPosted: Sun Jun 14, 2009 6:03 am Reply with quote
Munchieman
Beginner
Beginner
Joined: Jun 14, 2009
Posts: 2




Hello,
I haven't seen much here about zip files, so I may be barking up the wrong tree. I am attempting to crack a zip file I created a long time ago. It is a zip file that is about 850K named temppix.zip. It contains 1 file called other pix. The file is encrypted too. I tried using the Passware software for a few days, but I'm past all of the normal short cuts, and using simple brute force. I don't ever remember using a password that is less that 10 characters, and I don't have the months it will take to brute force the file.
After the various attacks, it comes up with some text that seems to include an MD5, but the online MD5 engines say that it isn't.

Protection: Zip 2.0 - Extraction Password, Default encryption
Complexity: Brute-force - Fast
MD5: 079D883C35C1B556BEBA786C65CD177D

Any suggestions on how I can open this file? Or, even get a list of the files that are within the otherpix.zip file?
Thanks for the help!
Munchieman
View user's profile Send private message
PostPosted: Sun Jun 14, 2009 9:17 am Reply with quote
waraxe
Site admin
Site admin
Joined: May 11, 2004
Posts: 2407
Location: Estonia, Tartu




Zip 2.0 encryption scheme is cryptographically weak and this is know allready long time, for example:

http://archive.cert.uni-stuttgart.de/vuln-dev/2003/02/msg00019.html

There are password crackers, which can decrypt ZIP archive contents within reasonable timeframe:

http://www.elcomsoft.com/archpr.html

Code:

Advanced Archive Password Recovery recovers protection passwords or unlocks encrypted ZIP and RAR archives created with all versions of popular archivers. Recover passwords for plain and self-extracting archives created with PKZip and WinZip, RAR and WinRAR automatically or with your assistance. Guaranteed unlocking of archives created with WinZip 8.0 and earlier in under one hour is possible by exploiting an implementation flaw.
View user's profile Send private message Send e-mail Visit poster's website
PostPosted: Mon Jun 15, 2009 4:27 pm Reply with quote
Munchieman
Beginner
Beginner
Joined: Jun 14, 2009
Posts: 2




Hey Waraxe,
Thanks for the reply. The weakness seems to be available when the file contains more than 3 to 5 files. I don't remember why, but I wanted to protect the file names, so I ziped the files into an encrypted archive that hides the filenames, and then zipped that archive into another encrypted archive.
The software you suggested has been tried, and says that it can't do the guaranteed zip crack because of there only being 1 file in the archive.
Any idea what kind of MD5 hash the Passware software showed?
MD5: 079D883C35C1B556BEBA786C65CD177D
Thanks again!
Munchieman
View user's profile Send private message
Cracking a zip file
www.waraxe.us Forum Index -> General discussion
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT
Page 1 of 1

Post new topicReply to topic


Powered by phpBB © 2001-2008 phpBB Group



Space Raider game for Android, free download - Space Raider gameplay video - Zone Raider mobile games
All logos and trademarks in this site are property of their respective owner. The comments and posts are property of their posters, all the rest (c) 2004-2024 Janek Vind "waraxe"
Page Generation: 0.035 Seconds