Re: MD5 Collisions...
- From: Eygene Ryabinkin <rea-fbsd@xxxxxxxxxxx>
- Date: Tue, 4 Dec 2007 18:40:58 +0300
Matt, good day.
Tue, Dec 04, 2007 at 09:19:58AM -0500, Matt Piechota wrote:
Norberto Meijome wrote:
I understand that the final nail in MD5's coffin hasn't been found
yet ( ie, we cannot "determine the exact original input given a
hash value") , but the fact that certain magic bytes can be found
(rather quickly) so that any 2 given binaries end up as collisions
seems , from my unlearned POV, more serious or sinister than what
the text above implies.
I think the big mitigating factor is that you can't easily generate a
message that has the same length as the original as well as the same hash.
No, read Kaminski's paper (http://www.doxpara.com/md5_someday.pdf):
with Wong's and Joux's multicollision attack (or its extensions)
one can generate files with the same sizes and MD5 hashes.
The usefullness of this with application to the ports collection
is questionable, since you should make two colliding archives and
both of them should be unpackable and the second should do some
evil things. But strictly speaking, there are attacks producing
files with the same size and MD5 hash.
http://www.cits.rub.de/MD5Collisions/ is also a good reading.
--
Eygene
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"
- Follow-Ups:
- Re: MD5 Collisions...
- From: Josh Paetzel
- Re: MD5 Collisions...
- References:
- MD5 Collisions...
- From: Norberto Meijome
- Re: MD5 Collisions...
- From: Colin Percival
- Re: MD5 Collisions...
- From: Norberto Meijome
- Re: MD5 Collisions...
- From: Matt Piechota
- MD5 Collisions...
- Prev by Date: Re: MD5 Collisions...
- Next by Date: Re: MD5 Collisions...
- Previous by thread: Re: MD5 Collisions...
- Next by thread: Re: MD5 Collisions...
- Index(es):