找回密码
 立即注册
查看: 2921|回复: 0
打印 上一主题 下一主题

爆破、破解Disduz x 2.5 md5(md5(pass)$salt)密码加密

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-14 00:03:14 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
测试环境4 ^3 k3 V( _, l: a# U0 s1 H
OS 名称: Microsoft® Windows Server® 2008 Enterprise
% W5 P: t  j: M! ]: G9 j' JOS 版本: 6.0.6001 Service Pack 1 Build 6001( Y, V+ H$ k! B7 S# {$ K
OS 制造商: Microsoft Corporation
7 n) g3 K8 W7 l" h! ?OS 配置: 独立服务器
$ ]' e/ \) [0 x4 C: z1 O% rOS 构件类型: Multiprocessor Free6 p- q. ?( M9 E6 J! X4 i0 z
注册的所有人: Windows 用户1 t1 C0 R3 W$ X' W% A7 ^4 c
系统型号: PowerEdge R620
! o9 \5 u9 U$ A( V0 J$ C系统类型: x64-based PC
6 O" d" q. w( o处理器: 安装了 1 个处理器。
7 q6 {( N$ b" R. G: J# U  s; `[01]: Intel64 Family 6 Model 45 Stepping 7 GenuineIntel ~2400& {) g$ I4 u# F2 ~& g* H: r
cat md5.txt
( ^; N5 e3 A' c/ J5 [4 I9 d# l; {1 ~3fb78e9bc0b297e3de4e77531766c37a:f29f95 /* = md5中无法查询的。*/
: l# S: }5 M8 L8 ~% k; s" P865a697fb9b4bd9c6737432aaff136bd:22dc87 /* = 304892415 */
% B! L* \" }  v2 D% {; ?15b7a21513f24ffe97d9f9830acf51ad:07626c /* = 123456 */
* C- b4 n) s- F2 F5 x& {' \! l+ g  U /* -a 使用穷举模式 -m HASH的类型是VB DISCUZ跟DV加密是一样,?d是代表数字 穷举10个数字 */ hashcat-cli64.exe -a 3 -m 2611 md5.txt ?d?d?d?d?d?d?d?d?d?d
0 I7 T3 O4 v4 {  z2 D0 LInput.Mode: Mask (?d?d?d?d?d)9 F2 i( t* }8 {! C# ^
Index…..: 0/1 (segment), 100000 (words), 0 (bytes)
" h0 g/ ~( B3 T. m) W' c5 ~$ A9 [4 eRecovered.: 0/3 hashes, 0/3 salts" U+ H3 m  K* j5 b# D
Speed/sec.: – plains, – words& L1 E8 r) y6 q1 G9 i
Progress..: 100000/100000 (100.00%)% e8 C9 ~! e. q+ Q$ l
Running…: –:–:–:–1 o# D0 I5 _5 V. z
Estimated.: –:–:–:–
! k0 H9 I7 ~6 q% ]15b7a21513f24ffe97d9f9830acf51ad:07626c:123456
: ^4 p( y! Z( VInput.Mode: Mask (?d?d?d?d?d?d); s1 w) g1 Y4 ?5 r: v' d# L
Index…..: 0/1 (segment), 1000000 (words), 0 (bytes)
8 \% {% `" c. P6 g; URecovered.: 1/3 hashes, 1/3 salts6 W# D1 R- a7 [4 @, f
Speed/sec.: 7.43M plains, 3.72M words6 i6 E- @$ {! F4 z) c
Progress..: 1000000/1000000 (100.00%)% s" K; M' h; [% N. J# j. h
Running…: 00:00:00:01
* ?+ G, e, K' l# L" c+ K7 ~  jEstimated.: –:–:–:–6 _, ^% e  T& `4 I! k7 l4 D
Input.Mode: Mask (?d?d?d?d?d?d?d)  s+ d! C- C/ H8 P" E
Index…..: 0/1 (segment), 10000000 (words), 0 (bytes)
4 F) I* x( M% z0 W& A; n  f3 Q! L; E% QRecovered.: 1/3 hashes, 1/3 salts
) e" o0 _2 z8 ASpeed/sec.: 13.67M plains, 6.83M words
8 h) e2 l' f' |% B9 oProgress..: 10000000/10000000 (100.00%)
5 }  f2 a5 K8 l8 ^: y2 J4 ?Running…: 00:00:00:01
& ]4 F2 y1 K: _! a# VEstimated.: –:–:–:–
0 e  [2 v, Q. m* ]" p7 KInput.Mode: Mask (?d?d?d?d?d?d?d?d)% P1 I: k) ?1 Z  W& y
Index…..: 0/1 (segment), 100000000 (words), 0 (bytes)% ]- T1 f: \2 M. o& V. v1 f
Recovered.: 1/3 hashes, 1/3 salts- @' M/ h7 m0 a0 u7 X
Speed/sec.: 18.59M plains, 9.29M words% @( I' ~  a  y: z8 ]
Progress..: 100000000/100000000 (100.00%)
; R: r# M: z: O9 Z4 `5 uRunning…: 00:00:00:11
' A* ^$ d4 i+ q8 u4 U* iEstimated.: –:–:–:–/ l: M! |, @; `, P' d# V
865a697fb9b4bd9c6737432aaff136bd:22dc87:304892415; w! n/ a% {% M7 v% J# p
可以看到破解 9位3开纯数字密码需要11秒。
8 y, ?: w# K5 d7 `  u9 cInput.Mode: Mask (?d?d?d?d?d?d?d?d?d?d)
  Q4 l* h! q+ t0 o( A+ [  M, m2 T$ Z% YIndex…..: 0/1 (segment), 10000000000 (words), 0 (bytes)
7 E( e. ^1 m8 z* ]; p" h/ jRecovered.: 2/3 hashes, 2/3 salts
0 A7 ^3 t& M. L0 HSpeed/sec.: 12.70M plains, 12.70M words
$ m4 R5 J& b" V7 H  E$ CProgress..: 10000000000/10000000000 (100.00%)0 k/ E+ t& u9 e% ]% `; w
Running…: 00:00:13:07
# U3 P' a' D# ^Estimated.: –:–:–:–
! A  U& k8 V9 M2 V0 ], |而10个数字即需要13分钟,这样的速度如果有服务器是8核或更多,或者自己GPU强劲,会更加快,我测试只是用了一个入门级的CPU。# q  |' l0 k' Y) P( \
在这里可以下载到一些字典,不过国人对这些字典貌似无视。5 n- f( w. {! ~+ {+ L
http://blog.g0tmi1k.com/2011/06/dictionaries-wordlists.html
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表