Re: Report of collision-generation with MD5

mario.lobo_at_ipad.com.br
Date: 08/18/04

  • Next message: Matthew Seaman: "Re: Report of collision-generation with MD5"
    To: "Peter C. Lai" <sirmoo@cowbert.net>
    Date: Wed, 18 Aug 2004 16:27:26 -0300
    
    

    How about a password hash? Wouldn´t those collisions enable the criation of a different password
    with the same hash?

    -- 
       //|  //||
      // | // ||
    -//--//---|| ARIO LOBO
    //  //    ||
    ---------------------------------
    mario.lobo@ipad.com.br
    http://www.ipad.com.br
    On 18 Aug 2004 at 14:29, Peter C. Lai wrote:
    > On Wed, Aug 18, 2004 at 09:08:12PM +0300, Claudiu wrote:
    > > hello,
    > > 
    > > please explain what do you mean by "reverse the hash". Is this the 
    > > recreation of the originial message from its hash ?
    > 
    > The short answer is yes. The slightly longer answer is that such is only one
    > specific case. The general case is that the digest should not reveal any 
    > information about the original message.
    > 
    > _______________________________________________
    > freebsd-security@freebsd.org mailing list
    > http://lists.freebsd.org/mailman/listinfo/freebsd-security
    > To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Matthew Seaman: "Re: Report of collision-generation with MD5"

    Relevant Pages

    • Re: NetScreen Password Hash
      ... The netscreens use MD5 hashes with the consonants of the word ... NETSCREEN spelled backwords in the hash. ... password hash or a tool to crack the password hash of netscreen 204 config ...
      (Pen-Test)
    • Re: NetScreen Password Hash
      ... I read somewhere that netscreen inserts consonants of the word 'netscreen' backwards into the hash. ... password hash or a tool to crack the password hash of netscreen 204 config ... Need to secure your web apps NOW? ...
      (Pen-Test)
    • RE: Threat vector of running a service using a domain account
      ... does send an NT password hash. ... you can capture the pre-authentication traffic, ... That's the beauty of Kerberos, after the initial auth, the password hash ...
      (Security-Basics)
    • Re: [Full-disclosure] password hash, funny myth in the industry!
      ... Hash: SHA1 ... blah blah blah, this is full-disclosure not some dear diary/myspace ... just password hash(generally SHA1, ... Full-Disclosure - We believe in it. ...
      (Full-Disclosure)
    • Re: phpBB Security Bugs
      ... hex digit in the md5 hash, and allows you to guess that digit's particular ... Each digit would be guessed in 16 tries or less. ... determine any particular password hash. ...
      (Bugtraq)