找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2054|回复: 0
打印 上一主题 下一主题

爆破、破解Disduz x 2.5 md5(md5(pass)$salt)密码加密

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-14 00:03:14 | 显示全部楼层 回帖奖励 |倒序浏览 |阅读模式
测试环境
+ {; [0 X0 u5 @% qOS 名称: Microsoft® Windows Server® 2008 Enterprise
; ^( I7 l  M& @' GOS 版本: 6.0.6001 Service Pack 1 Build 6001
1 A. t) F4 T% R% }# g0 [OS 制造商: Microsoft Corporation' o! l3 A0 U6 m8 T% }( m
OS 配置: 独立服务器- |7 U( O, F6 f/ ]: G0 ?9 M
OS 构件类型: Multiprocessor Free
% y0 g7 s# I9 ~0 W: N! E2 L# f注册的所有人: Windows 用户
& W2 b2 ]8 [& e& \# ?: ]# k( b系统型号: PowerEdge R620
& [  J5 D# [4 {2 u/ k8 {$ F5 F系统类型: x64-based PC
3 C1 J) D# O" s! a; B处理器: 安装了 1 个处理器。
; z' p# _, v$ @* U  E[01]: Intel64 Family 6 Model 45 Stepping 7 GenuineIntel ~2400- a, W7 T- S5 ]; U3 E0 r0 s
cat md5.txt5 J* \+ t- i8 k* y3 b, O& I
3fb78e9bc0b297e3de4e77531766c37a:f29f95 /* = md5中无法查询的。*/+ c4 J0 A  u7 ^+ g. E/ t
865a697fb9b4bd9c6737432aaff136bd:22dc87 /* = 304892415 */, a! M; F4 A. |: A3 G  O# a- h
15b7a21513f24ffe97d9f9830acf51ad:07626c /* = 123456 */. }+ _& Z" m, q
/* -a 使用穷举模式 -m HASH的类型是VB DISCUZ跟DV加密是一样,?d是代表数字 穷举10个数字 */ hashcat-cli64.exe -a 3 -m 2611 md5.txt ?d?d?d?d?d?d?d?d?d?d$ r3 k- l% g/ `# q4 x1 X
Input.Mode: Mask (?d?d?d?d?d)# p% t) E' {0 \
Index…..: 0/1 (segment), 100000 (words), 0 (bytes)) J1 V% {) o' S: m
Recovered.: 0/3 hashes, 0/3 salts
" r+ a' j$ d6 |Speed/sec.: – plains, – words& w' ^  i* I+ b  B( j( J( G0 U
Progress..: 100000/100000 (100.00%)4 |. K% Z9 W1 {' g% R- E
Running…: –:–:–:–
, C" V1 j  s( p8 \Estimated.: –:–:–:–& }5 f* s6 ]: z+ s" S/ y* v
15b7a21513f24ffe97d9f9830acf51ad:07626c:1234560 y0 {8 B5 A/ E' s2 W
Input.Mode: Mask (?d?d?d?d?d?d)9 `- P( P! n1 D9 R$ {
Index…..: 0/1 (segment), 1000000 (words), 0 (bytes)0 `/ B) F& P1 h/ n$ A+ _0 a
Recovered.: 1/3 hashes, 1/3 salts
& H+ L' e! V3 `9 U) ~9 l+ t/ zSpeed/sec.: 7.43M plains, 3.72M words
/ B6 A% V. z# L4 K9 U8 QProgress..: 1000000/1000000 (100.00%)
& |% g( y  ^/ T' N) yRunning…: 00:00:00:01
9 p: o. y8 y, w, o/ `Estimated.: –:–:–:–
4 X* E9 d. T% Y3 uInput.Mode: Mask (?d?d?d?d?d?d?d)6 x% J/ C/ L1 M- }( v7 W2 D
Index…..: 0/1 (segment), 10000000 (words), 0 (bytes)
! X0 ~3 m7 I, Y# V$ }6 i' h% dRecovered.: 1/3 hashes, 1/3 salts
* i2 V- J9 N+ V% U! P* J8 YSpeed/sec.: 13.67M plains, 6.83M words
8 Q5 u' N0 ?* i- D" mProgress..: 10000000/10000000 (100.00%)
2 v, h- F$ x; Y) x3 _& |8 GRunning…: 00:00:00:01
) e& W6 N, V1 h- i+ c& }/ pEstimated.: –:–:–:–
0 y+ u$ {  F) J" Q  `Input.Mode: Mask (?d?d?d?d?d?d?d?d)
5 K' ?- Y- K; |3 I$ d4 }. ^( p, |Index…..: 0/1 (segment), 100000000 (words), 0 (bytes)8 x' p" y& U" P6 y$ `1 Q
Recovered.: 1/3 hashes, 1/3 salts
, q6 H3 g: S; y0 WSpeed/sec.: 18.59M plains, 9.29M words  ?+ u) Q5 D3 Q0 T
Progress..: 100000000/100000000 (100.00%)
0 J: U% L/ H, F- S6 PRunning…: 00:00:00:11
& P6 W9 n3 X4 _; w! d( ~# ^- d. DEstimated.: –:–:–:–
6 E" {5 }! }+ V% |0 R+ S$ I7 C; c865a697fb9b4bd9c6737432aaff136bd:22dc87:304892415
+ y$ r0 A! U% U5 _可以看到破解 9位3开纯数字密码需要11秒。0 I2 U% a' W9 ~+ h6 g
Input.Mode: Mask (?d?d?d?d?d?d?d?d?d?d)
5 e: x: q# Z% z* o2 F& kIndex…..: 0/1 (segment), 10000000000 (words), 0 (bytes)7 y) D! B5 s, K: b4 p: y
Recovered.: 2/3 hashes, 2/3 salts8 \3 @, Q- j. L  W0 j$ i0 T+ [1 F7 u
Speed/sec.: 12.70M plains, 12.70M words
$ M1 L6 A1 {! GProgress..: 10000000000/10000000000 (100.00%)
& O- E: ^; d1 k% {& L, SRunning…: 00:00:13:07
) F2 D% C1 M; d7 gEstimated.: –:–:–:–9 a- g  a) s: F, N& Z
而10个数字即需要13分钟,这样的速度如果有服务器是8核或更多,或者自己GPU强劲,会更加快,我测试只是用了一个入门级的CPU。
* J  e! F! t& r* k/ }7 o在这里可以下载到一些字典,不过国人对这些字典貌似无视。8 T' E2 S3 P4 |
http://blog.g0tmi1k.com/2011/06/dictionaries-wordlists.html
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表