Re: Report of collision-generation with MD5

From: Jan Grant (Jan.Grant_at_bristol.ac.uk)
Date: 08/19/04

  • Next message: Tig: "Re: Report of collision-generation with MD5"
    Date: Thu, 19 Aug 2004 11:26:47 +0100 (BST)
    To: Brett Glass <brett@lariat.org>
    
    

    On Wed, 18 Aug 2004, Brett Glass wrote:

    > At 02:54 PM 8/18/2004, Chris Doherty wrote:
    >
    > >what you can do, if you have a proper attack formula, is find *a* message
    > >that produces *that one hash*. that is, if I have message M which produces
    > >hash H, I can use the attack to find *a* message M' which will also
    > >produce hash H.
    >
    > The thing is, passwords are short and have limited entropy. Chances are,
    > if you find a password that produces the same hash, it's M.

    Details in the paper are few, but I don't think what Chris describes in
    the snippet Brett quotes is what's necessarily happening. That is, for
    any given MD5 initial state, they seem to be saying that they can find
    two related messages that produce the same hash. NOT that they
    necessarily can find a message with the same has as a _given_ message.
    Which I guess means that they can tack two different strings on the end
    of any arbitrary file (since they claim they can attack an arbitrary IV)
    and the resulting two files will also have the same MD5 hash, but that
    won't be the MD5 of the original. The two appended strings are
    effectively random, and differ from each other only in a few bits.

    -- 
    jan grant, ILRT, University of Bristol. http://www.ilrt.bris.ac.uk/
    Tel +44(0)117 9287088 Fax +44 (0)117 9287112 http://ioctl.org/jan/
    Hang on, wasn't he holding a wooden parrot? No! It was a porcelain owl.
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Tig: "Re: Report of collision-generation with MD5"

    Relevant Pages

    • Re: MD5 vs. SHA1 hashed passwords in /etc/master.passwd: can we configure SHA1 in /etc/login.conf?
      ... Hash: SHA1 ... md5, ... hash algorithms like des, md5, sha1, blf or even sha256. ... can compromise system passwords, as cryptmd5 scheme doesn't store ...
      (FreeBSD-Security)
    • Re: Password hashes
      ... NTLM hash as the key. ... There is however no locally stored NTLMV2 hash of passwords. ... Auditing and reviewing the security logs ... secure their network and data and the documentation to do such at TechNet ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Windows XP / 2K3 Default Users
      ... Cracking the 'passwords' has never been ... The gist of the 'technique' is the "Modifying Windows NT Logon Credential" ... existing windows applications that use the hash currently set to ... and then re-use those hashes to try to get authenticated access to other ...
      (Pen-Test)
    • Re: Writing U3060, U0C exists for QM
      ... If these are real passwords being stored, ... I concur the U3060 hash seems to be of low quality; I tried to use it when ... as part of any migration away from d3, since you cannot generate an md5 hash ... file items so the department manager can log on to staff accounts with that ...
      (comp.databases.pick)
    • Re: Pidgin IM Client Password Disclosure Vulnerability.
      ... because we need to be able to generate the hash a given ... Some protocols can ask for different types of hashes at ... passwords stored in it ... lost, you have much bigger problems than lost IM passwords. ...
      (Bugtraq)