New Practical Attacks on Digital Signatures Using MD5 Message Digest

From: Vlastimil Klima (v.klima_at_volny.cz)
Date: 12/09/04


Date: Thu, 9 Dec 2004 10:27:13 +0100

There is another example about MD5 obscurity by Ondrej Mikle, sent to
eprint.iacr.org on 2nd December.

Abstract
We use the knowledge of the single MD5 collision published by Wang et al.
[1] to show an example of a pair of binary self-extract packages with equal
MD5 checksums, whereas resulting extracted contracts have fundamentally
different meaning. Secondly, we demonstrate how an attacker could create
custom pair of such packages containing files arbitrarily chosen by the
attacker with equal MD5 sums where each of the package extracts different
file. Once the algorithm for finding MD5 collisions is published, attack
could be made even more effective as we explain further. Authors of [1]
claim to know such algorithm for any MD5 initialization vector. A real-world
scenario of such attack is outlined. Finally, we point out the consequences
resulting from such attack for signature schemes based on MD5 message digest
on an example using GPG.

The paper is available at the following link:
http://cryptography.hyperlink.cz/2004/collisions.htm
Vlastimil Klima

[1] X. Wang, D. Feng, X. Lai, H. Yu, "Collisions for Hash Functions MD4,
MD5, HAVAL-128 and RIPEMD", rump session, CRYPTO 2004, Cryptology ePrint
Archive, Report 2004/199, http://eprint.iacr.org/2004/199



Relevant Pages

  • Re: SHA-1 vs. triple-DES for password encryption?
    ... even if the attack wasn't practical. ... > somehow break MD5 that was not done since 1992? ... >>> the hash algorithms as MD5 and MD4. ... >> than you would of SHA1 to get the difficulty up to the same level. ...
    (SecProg)
  • [REVS] Multiple Collisions attack on MD5 and other Hashing Algorithms
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... This collision attack might someday introduce a weakness in MD5 ... The presented attack can find many real collisions which are ...
    (Securiteam)
  • Re: MD5CRK is now LIVE
    ... >> We agree that a collision does not help against a password system. ... >> In the case of a contract, the attack won't work on a document ... note that unless MD5CRK is setup right from the start ... Anyone relying on the difficulty to find MD5 collision ...
    (sci.crypt)
  • Re: SHA-1 vs. triple-DES for password encryption?
    ... > birthday attack succeeds with probability 0.5 or 50%. ... > full MD5. ... > theoretical cryptographers call an "attack" create FUD on this issue. ... Note that you are correct in saying that SHA1 is of the same family as ...
    (SecProg)
  • Re: Lost password + MD5 ?
    ... >> hash M, and being able to produce a different plaintext B that has the ... which MD5 attack are you referring to? ...
    (comp.lang.php)

Quantcast