找回密码
 立即注册
查看: 2924|回复: 0
打印 上一主题 下一主题

爆破、破解Disduz x 2.5 md5(md5(pass)$salt)密码加密

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-14 00:03:14 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
测试环境
! }7 C$ \, K  H0 Z4 H& MOS 名称: Microsoft® Windows Server® 2008 Enterprise
4 D' V/ n$ \  O% f7 v+ A3 B! |OS 版本: 6.0.6001 Service Pack 1 Build 6001
0 v# o! C. ?) XOS 制造商: Microsoft Corporation7 w9 H; l" l( K; A
OS 配置: 独立服务器& R2 F: i$ s0 x1 S# m0 y" [0 {8 a
OS 构件类型: Multiprocessor Free
4 I# r* i3 a; I5 G注册的所有人: Windows 用户
2 r$ d3 T# t! a: c0 k& U系统型号: PowerEdge R620$ [+ }4 Q  e# d4 Q; _" i
系统类型: x64-based PC
1 p; A6 z& K4 _- ?处理器: 安装了 1 个处理器。& O' I, Z6 s! q) h3 [9 h4 N  r
[01]: Intel64 Family 6 Model 45 Stepping 7 GenuineIntel ~2400' @2 }: |, {$ V- i& s) d
cat md5.txt
, e% T0 t# Y) z+ j. V) Q3fb78e9bc0b297e3de4e77531766c37a:f29f95 /* = md5中无法查询的。*/: N' k& f( _- A' }; P8 M# Z% s
865a697fb9b4bd9c6737432aaff136bd:22dc87 /* = 304892415 */
# W! q/ c, K# }4 u* G/ R6 t15b7a21513f24ffe97d9f9830acf51ad:07626c /* = 123456 */, i  D& }  b: Y& `1 U. k
/* -a 使用穷举模式 -m HASH的类型是VB DISCUZ跟DV加密是一样,?d是代表数字 穷举10个数字 */ hashcat-cli64.exe -a 3 -m 2611 md5.txt ?d?d?d?d?d?d?d?d?d?d
5 B2 ?8 b( g' o, IInput.Mode: Mask (?d?d?d?d?d)
2 R( {  T* m  G. [Index…..: 0/1 (segment), 100000 (words), 0 (bytes)
/ V. b% Z1 u& Y6 q: m3 hRecovered.: 0/3 hashes, 0/3 salts/ P! W9 c9 g( I
Speed/sec.: – plains, – words
/ t& k( P+ Q! l# m, @' R8 s5 E, bProgress..: 100000/100000 (100.00%)5 c) c' }: R" t) ^0 H! [7 ]3 w
Running…: –:–:–:–8 m2 y- [: j0 u' V& J8 n
Estimated.: –:–:–:–, V# k+ a/ h" f/ Z  q5 w( n1 _
15b7a21513f24ffe97d9f9830acf51ad:07626c:1234560 a; O9 _8 R; K# p
Input.Mode: Mask (?d?d?d?d?d?d)
0 L0 u( q% @0 o) k+ O+ w8 ~Index…..: 0/1 (segment), 1000000 (words), 0 (bytes)
( L7 a' h2 Q2 I' x# g8 }Recovered.: 1/3 hashes, 1/3 salts& ^9 ~( K5 L1 H0 ^+ I% i
Speed/sec.: 7.43M plains, 3.72M words
0 k3 @9 u: n8 O* ~9 k7 O9 i/ ]( yProgress..: 1000000/1000000 (100.00%)/ v- d6 g: ^. k# m
Running…: 00:00:00:01
# W/ p1 m8 J+ X; ~$ cEstimated.: –:–:–:–" J7 Y0 @  w: P
Input.Mode: Mask (?d?d?d?d?d?d?d)
; I6 a2 r7 Z$ o" i/ @Index…..: 0/1 (segment), 10000000 (words), 0 (bytes)1 O3 l* j9 V4 k5 I- |5 Y3 f
Recovered.: 1/3 hashes, 1/3 salts
9 X- O/ }% U: {4 sSpeed/sec.: 13.67M plains, 6.83M words9 t* V8 ?4 {% W9 r
Progress..: 10000000/10000000 (100.00%)7 V7 |* z& z: B9 X: S- t6 b
Running…: 00:00:00:01) k* O$ `( k: y3 \/ Q. u) B2 F
Estimated.: –:–:–:–
9 G4 ?9 T% t* K- G( jInput.Mode: Mask (?d?d?d?d?d?d?d?d)
* L0 A$ r' F) q3 w: xIndex…..: 0/1 (segment), 100000000 (words), 0 (bytes)% U- n3 O% p8 k  S
Recovered.: 1/3 hashes, 1/3 salts
6 I& o: `. F6 o  ESpeed/sec.: 18.59M plains, 9.29M words( [4 P4 U+ Y# a3 B/ l
Progress..: 100000000/100000000 (100.00%); S& H3 j# x( e
Running…: 00:00:00:115 k+ l! \1 D& T' \5 b+ i/ K# f% q
Estimated.: –:–:–:–9 p0 e+ U; A1 m6 G* k6 L; N
865a697fb9b4bd9c6737432aaff136bd:22dc87:3048924157 M3 r/ ?  u) f& c. ^
可以看到破解 9位3开纯数字密码需要11秒。
1 T- l9 J1 C! y) I+ QInput.Mode: Mask (?d?d?d?d?d?d?d?d?d?d)
$ J; i( h* _7 {$ M# m1 xIndex…..: 0/1 (segment), 10000000000 (words), 0 (bytes)3 d; B' T' c# G5 Q/ e) ~
Recovered.: 2/3 hashes, 2/3 salts
* N, ^" Q* o- m0 a/ H- b4 XSpeed/sec.: 12.70M plains, 12.70M words
! v6 z0 k: t2 R& {+ |Progress..: 10000000000/10000000000 (100.00%)
5 U# r7 b. x# @8 V' z% Q$ ^* qRunning…: 00:00:13:07
$ Z  F2 E; K: `' fEstimated.: –:–:–:–0 j6 m3 K8 B" r3 ^- d
而10个数字即需要13分钟,这样的速度如果有服务器是8核或更多,或者自己GPU强劲,会更加快,我测试只是用了一个入门级的CPU。- z' y2 d3 b2 r' I: z3 N9 x
在这里可以下载到一些字典,不过国人对这些字典貌似无视。
( f1 {) I! q$ E4 k. @/ Khttp://blog.g0tmi1k.com/2011/06/dictionaries-wordlists.html
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表